CVE-2025-41734

EUVD-2025-197984
An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.
PHP Remote File Inclusion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
metz-connectewio2-m_firmware
𝑥
< 2.2.0
metz-connectewio2-m-bm_firmware
𝑥
< 2.2.0
metz-connectewio2-bm_firmware
𝑥
< 2.2.0
𝑥
= Vulnerable software versions