PT-2026-7598 · Metis Dfs · Metis Dfs

Or Balog

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2026-2249

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions METIS DFS versions prior to oscore 2.1.234-r18
Description METIS DFS devices expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges, resulting in the compromise of the software and granting unauthorized access to modify configuration, read and alter sensitive data, or disrupt services.
Recommendations For versions prior to oscore 2.1.234-r18, restrict access to the /console endpoint. For versions prior to oscore 2.1.234-r18, disable the web-based shell if it is not required.

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-2249

Affected Products

Metis Dfs