CVE-2026-25818
Received
Received - Intake
Weak Entropy in HMS Networks Ewon Flexy Authentication Cookies
Publication date: 2026-03-13
Last updated on: 2026-03-13
Assigner: MITRE
Description
Description
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hms_networks | cosy_plus | to 22.1s6 (exc) |
| hms_networks | cosy_plus | to 23.0s3 (exc) |
| hms_networks | ewon_flexy | to 15.0s4 (exc) |
| hms_networks | cosy | to 22.1s6 (exc) |
| hms_networks | cosy | to 23.0s3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-315 | The product stores sensitive information in cleartext in a cookie. |