CVE-2026-25819
Received
Received - Intake
Denial of Service in HMS Networks Ewon Flexy and Cosy+ GUI
Publication date: 2026-03-13
Last updated on: 2026-03-13
Assigner: MITRE
Description
Description
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have access to the device's GUI.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hms_networks | ewon_flexy | to 15.0s4 (exc) |
| hms_networks | cosy+ | to 22.1s6 (exc) |
| hms_networks | cosy+ | to 23.0s3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |