PT-2026-25078 · Undefined · Undefined
Published
2026-03-12
·
Updated
2026-03-14
·
CVE-2026-25817
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HMS Networks Ewon Flexy versions prior to 15.0s4
HMS Networks Ewon Cosy+ versions 22.xx prior to 22.1s6
HMS Networks Ewon Cosy+ versions 23.xx prior to 23.0s3
Description
The software contains improper neutralization of special elements used in an OS command, which could allow remote code execution. An attacker with low privilege access on the gateway, who has credentials, can exploit this issue.
Recommendations
Update HMS Networks Ewon Flexy to version 15.0s4 or later.
Update HMS Networks Ewon Cosy+ to version 22.1s6 or later.
Update HMS Networks Ewon Cosy+ to version 23.0s3 or later.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined