CVE-2014-2717: Honeywell Falcon Xlweb Linux Controller

High severity, CVSS 7.6. EPSS: 3.7% chance of exploitation in the next 30 days.

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.

Affected products

  • Honeywell Falcon Xlweb Linux Controller: up to and including 2.04.01
  • Honeywell Falcon Xlweb Xlwebexe: up to and including 2.02.11

Published 2014-07-24. Last modified 2026-06-17.