CVE-2025-41733

EUVD-2025-197985
The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
metz-connectewio2-m_firmware
𝑥
< 2.2.0
metz-connectewio2-m-bm_firmware
𝑥
< 2.2.0
metz-connectewio2-bm_firmware
𝑥
< 2.2.0
𝑥
= Vulnerable software versions