CVE-2023-25178: Honeywell c300 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

Affected products

  • Honeywell c300 Firmware: from 501.1, up to and including 501.6hf8; from 510.1, up to and including 510.2hf12; from 511.1, up to and including 511.5tcu3; from 520.1, up to and including 520.1tcu4; from 520.2, up to and including 520.2tcu2

Published 2023-07-13. Last modified 2026-06-17.