CVE-2025-41735

EUVD-2025-197983
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
metz-connectewio2-m_firmware
𝑥
< 2.2.0
metz-connectewio2-m-bm_firmware
𝑥
< 2.2.0
metz-connectewio2-bm_firmware
𝑥
< 2.2.0
𝑥
= Vulnerable software versions