Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2025-0432

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.
0
Attacker Value
Unknown

CVE-2024-9154

Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).
0
Attacker Value
Unknown

CVE-2024-7755

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and decode the credentials.
0
Attacker Value
Unknown

CVE-2024-33897

Disclosure Date: August 06, 2024 (last updated August 13, 2024)
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
Attacker Value
Unknown

CVE-2024-33896

Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
Attacker Value
Unknown

CVE-2024-33895

Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
Attacker Value
Unknown

CVE-2024-33893

Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
Attacker Value
Unknown

CVE-2024-33892

Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
Attacker Value
Unknown

CVE-2024-6558

Disclosure Date: July 25, 2024 (last updated August 14, 2024)
HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input fields and store the HTML code. The stored HTML code will be embedded in the page and executed by host browser the next time the page is loaded, enabling social engineering attacks.
Attacker Value
Unknown

CVE-2021-33214

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.