The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
History

Wed, 19 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Metz Connect
Metz Connect ewio2
Vendors & Products Metz Connect
Metz Connect ewio2

Tue, 18 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 10:30:00 +0000

Type Values Removed Values Added
Description The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Title Possible malfunction credential injection
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2025-11-18T21:17:53.438Z

Reserved: 2025-04-16T11:17:48.319Z

Link: CVE-2025-41733

cve-icon Vulnrichment

Updated: 2025-11-18T21:17:49.287Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-18T11:15:46.700

Modified: 2025-11-18T14:06:29.817

Link: CVE-2025-41733

cve-icon Redhat

No data.