← All CVEs

CVE-2025-41733

critical · 9.8

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.

9.8
CVSS
0.6%
EPSS (exploit prob.)
49th
EPSS percentile
2025-11-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-305

Affected products

VendorProductAffected versions
metz-connectewio2-m_firmware< 2.2.0
metz-connectewio2-mall versions
metz-connectewio2-m-bm_firmware< 2.2.0
metz-connectewio2-m-bmall versions
metz-connectewio2-bm_firmware< 2.2.0
metz-connectewio2-bmall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-41733