CVE-2025-41735
18.11.2025, 11:15
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.Enginsight
| Vendor | Product | Version |
|---|---|---|
| metz-connect | ewio2-m_firmware | 𝑥 < 2.2.0 |
| metz-connect | ewio2-m-bm_firmware | 𝑥 < 2.2.0 |
| metz-connect | ewio2-bm_firmware | 𝑥 < 2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration