CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “metz-connect”

5 vulnerabilities found for “metz-connect”

CVE-2025-41733
CRITICAL9.8

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.

metz-connect / ewio2-m_firmware+2
Network
Published Nov 18, 2025
CVE-2025-41737
HIGH7.5

Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.

metz-connect / ewio2-m_firmware+2
Network
Published Nov 18, 2025
CVE-2025-41735
HIGH8.8

A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.

metz-connect / ewio2-m_firmware+2
Network
Published Nov 18, 2025
CVE-2025-41736
HIGH8.8

A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.

metz-connect / ewio2-m_firmware+2
Network
Published Nov 18, 2025
CVE-2025-41734
CRITICAL9.8

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

metz-connect / ewio2-m_firmware+2
Network
Published Nov 18, 2025