Home
HIGH: 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version
affected
Description
A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version
Credits
Thomas Fankhauser (CyberDanube)
References
seclists.org/fulldisclosure/2024/Dec/18
cyberdanube.com/...-remote-code-execution-in-ewon-flexy-205/