CVE-2026-25823
Received
Received - Intake
Stack Buffer Overflow in HMS Networks Ewon Flexy Causes DoS, RCE
Publication date: 2026-03-13
Last updated on: 2026-03-13
Assigner: MITRE
Description
Description
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauthenticated Remote Code Execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hms_networks | ewon_flexy | to 15.0s4 (exc) |
| hms_networks | cosy | to 22.1s6 (exc) |
| hms_networks | cosy | to 23.0s3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |