CVE-2025-41733
18.11.2025, 11:15
The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.Enginsight
| Vendor | Product | Version |
|---|---|---|
| metz-connect | ewio2-m_firmware | 𝑥 < 2.2.0 |
| metz-connect | ewio2-m-bm_firmware | 𝑥 < 2.2.0 |
| metz-connect | ewio2-bm_firmware | 𝑥 < 2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration