CVE-2026-25817
Last modified
CVE-2026-25817 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provided the attacker has credentials.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provided the attacker has credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-25817?
How severe is CVE-2026-25817?
How do I fix CVE-2026-25817?
Are you affected by CVE-2026-25817?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
