Python 3 PoC for **[CVE-2026-13249]( — **Honeywell PD45 Industrial Printer** web management interface.
**CVE-2026-13249** — Firmware **F10.19.010040** through **before F10.22.030745** exposes an **unauthenticated arbitrary file upload** on the printer **HTTPS web admin** (CWE-306, CWE-434, CWE-78). Attackers can upload attacker-controlled files that may be **executed as commands** on the device (**RCE**). CVSS **9.8 Critical** (`AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`). **Fix:** upgrade to **F10.22.030745** or newer; restrict web UI to trusted management networks.
**PoC page:** [
**Vendor:** [Honeywell product security notices](
Catalog: [
| **Product** | Honeywell PD45 Industrial Printer |
| **Affected firmware** | **≥ F10.19.010040** and **< F10.22.030745** |
| **Fixed firmware** | **F10.22.030745** |
| **Interface** | Web management (HTTPS, default creds documented as `itadmin` / `pass` for *authenticated* flows) |
Honeywell’s public advisory does not publish the exact unauthenticated upload URI. This PoC **fingerprints** the device and firmware, optionally **scrapes multipart forms** under `/Manage/` and `/Services/`, and supports **`--upload-url`** from your own capture on a lab unit.
python poc.py -u --mode check
python poc.py -u --mode check --upload-probe
python poc.py -u --mode exploit \
--upload-url " --field file \
--verify-url "
python poc.py --list targets.example.txt --mode check -j 8
Authorized testing on printers you own or have explicit permission to assess. `--upload-probe` / `--mode exploit` write data to the target device.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
