LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-25817

CVE-2026-25817 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 16, 2026

HMS Networks Ewon - Command Injection

Published: March 13, 2026Updated: March 16, 2026Remote Exploitable

Overview

HMS Networks Ewon Flexy < 15.0s4, Cosy+ 22.xx < 22.1s6, and Cosy+ 23.xx < 23.0s3 contain a command injection caused by improper neutralization of special elements in OS commands, letting attackers with low privilege credentials execute code remotely.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 29.1%(Probability of exploitation in next 30 days)

Impact

Attackers with low privilege credentials can execute arbitrary code remotely, potentially compromising the gateway.

Mitigation

Update to firmware 15.0s4 for Flexy, 22.1s6 for Cosy+ 22.xx, and 23.0s3 for Cosy+ 23.xx or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 14, 2026

🟠 CVE-2026-25817 - High (8.8) HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by atta... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-25817/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-25817
Severity
High
CVSS Score
8.8
Type
command_injection
Status
unconfirmed
EPSS
29.1%
Social Posts
1

CWE

  • CWE-94

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

29.1%Probability of exploitation in the next 30 days