CVE-2023-5878: Honeywell Onewireless Network Wireless Device Manager

Critical severity, CVSS 9.4. EPSS: 1% chance of exploitation in the next 30 days.

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to R322.3, R330.2 or the most recent version of this product2.

Affected products

  • Honeywell Onewireless Network Wireless Device Manager: from 310.1, up to and including 322.2; from 323.1, up to and including 330.1

Published 2025-02-06. Last modified 2026-06-17.