Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-13249 — Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-13249
Embedded Systems SecurityReconnaissanceIoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringHardware & IoT SecurityRemote Access Tool
GitHubmurrez/cve-2026-13249

CVE-2026-13249

7 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC

View Repository

CVE-2026-13249 — Honeywell PD45 Unauthenticated File Upload (RCE)

Python 3 PoC for CVE-2026-13249 — Honeywell PD45 Industrial Printer web management interface.

Description (PoCbit / GitHub)

CVE-2026-13249 — Firmware F10.19.010040 through before F10.22.030745 exposes an unauthenticated arbitrary file upload on the printer HTTPS web admin (CWE-306, CWE-434, CWE-78). Attackers can upload attacker-controlled files that may be executed as commands on the device (RCE). CVSS 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Fix: upgrade to F10.22.030745 or newer; restrict web UI to trusted management networks.

PoC page: https://pocbit.org/pocs/cve-2026-13249

Vendor: Honeywell product security notices

PoCbit

Catalog: https://pocbit.org/pocs/

ProductHoneywell PD45 Industrial Printer
Affected firmware≥ F10.19.010040 and < F10.22.030745
Fixed firmwareF10.22.030745
InterfaceWeb management (HTTPS, default creds documented as itadmin / pass for authenticated flows)
ImpactUnauth upload → RCE

Honeywell’s public advisory does not publish the exact unauthenticated upload URI. This PoC fingerprints the device and firmware, optionally scrapes multipart forms under /Manage/ and /Services/, and supports --upload-url from your own capture on a lab unit.

Usage

pip install -r requirements.txt

python poc.py -u https://10.10.10.50 --mode check
python poc.py -u https://10.10.10.50 --mode check --upload-probe
python poc.py -u https://10.10.10.50 --mode exploit \
  --upload-url "https://10.10.10.50/..." --field file \
  --verify-url "https://10.10.10.50/pocbit_13249.txt"
python poc.py --list targets.example.txt --mode check -j 8

FOFA / Shodan (examples)

title="Honeywell" && body="PD45"
ssl.cert.subject.cn="PD45"

Legal

Authorized testing on printers you own or have explicit permission to assess. --upload-probe / --mode exploit write data to the target device.

Download Tool