CVE-2025-41733: Possible malfunction credential injection
The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41733?
CVE-2025-41733 is classified as a high-severity vulnerability due to the potential for unauthorized access to root credentials.
How do I fix CVE-2025-41733?
To mitigate CVE-2025-41733, ensure that the affected Metz Connect Ewio2 firmware is updated to a secure version beyond 2.2.0.
Who is affected by CVE-2025-41733?
CVE-2025-41733 affects users of Metz Connect Ewio2, Ewio2-m, and Ewio2-bm firmware versions 2.2.0 and below.
What types of attacks can exploit CVE-2025-41733?
An unauthenticated remote attacker can exploit CVE-2025-41733 by sending specifically crafted POST requests to gain unauthorized root access.
Is CVE-2025-41733 specific to certain firmware versions?
Yes, CVE-2025-41733 specifically impacts Metz Connect Ewio2 firmware versions up to and including 2.2.0.