Integer Underflow Vulnerability in Honeywell Experion PKS and OneWireless WDM
CVE-2025-2523

9.4CRITICAL

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
10 July 2025

What is CVE-2025-2523?

The Honeywell Experion PKS and OneWireless WDM are subject to an integer underflow vulnerability in the Control Data Access (CDA) component. This flaw can be exploited by an attacker to manipulate communication channels, which may result in erroneous calculations during subtraction operations. If successfully exploited, it could lead to remote code execution, posing significant security risks. Honeywell advises users to update to the latest versions: Experion PKS: 520.2 TCU9 HF1 and 530.1 TCU3 HF1, and OneWireless: 322.5 and 331.1 to mitigate this vulnerability.

Affected Version(s)

C200E Experion PKS 520.1 <= 520.2 TCU9

C200E Experion PKS 530 <= 530 TCU3

C300 PCNT02 Experion PKS 520.1 <= 520.2 TCU9

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Positive Technologies
.
CVE-2025-2523 : Integer Underflow Vulnerability in Honeywell Experion PKS and OneWireless WDM