CVE-2025-41736: Possible arbitrary code execution
Published Nov 18, 2025
·Updated
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.
Affected Software
6 affected components
All of the following
Metz-connect Ewio2-m Firmware<2.2.0
Metz-connect Ewio2-m
All of the following
Metz-connect Ewio2-m-bm Firmware<2.2.0
Metz-connect Ewio2-m-bm
All of the following
Metz-connect Ewio2-bm Firmware<2.2.0
Metz-connect Ewio2-bm
Event History
Nov 18, 2025
CVE Published
via MITRE·10:18 AM
Data Sourced
via MITRE·10:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41736?
CVE-2025-41736 is classified as a low-severity vulnerability that allows a remote code execution due to path traversal.
2
How can I fix CVE-2025-41736?
To mitigate CVE-2025-41736, ensure that you upgrade the affected Metz-connect Ewio2 firmware to a version above 2.2.0.
3
What types of systems are affected by CVE-2025-41736?
CVE-2025-41736 affects the Metz-connect Ewio2-m, Ewio2-m-bm, and Ewio2-bm firmware versions below 2.2.0.
4
What are the potential risks of CVE-2025-41736?
The potential risks of CVE-2025-41736 include unauthorized execution of arbitrary Python scripts on vulnerable systems.
5
Can CVE-2025-41736 be exploited remotely?
Yes, CVE-2025-41736 can be exploited by low privileged remote attackers to execute code.