Honeywell OneWireless Wireless Device Manager Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Honeywell OneWireless Wireless Device Manager (WDM) versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, and R330.1. This vulnerability allows an authenticated attacker to exploit the firmware update process, potentially leading to command injection.

Impact

Exploitation of this vulnerability could result in unauthorized command execution on the affected system.

Remediation

Users are advised to update to version R322.3, R330.2, or the latest version of the product.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
10.0
exploitability
4.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.