LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-25823

CVE-2026-25823 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 16, 2026

HMS Networks Ewon - Buffer Overflow

Published: March 13, 2026Updated: March 16, 2026Remote Exploitable

Overview

HMS Networks Ewon Flexy < 15.0s4, Cosy+ 22.xx < 22.1s6, and Cosy+ 23.xx < 23.0s3 contain a stack buffer overflow in firmware, letting unauthenticated remote attackers cause denial of service or execute code remotely, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 25.6%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can cause denial of service or execute arbitrary code remotely, potentially compromising the device.

Mitigation

Update to firmware versions 15.0s4, 22.1s6, 23.0s3 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 14, 2026

šŸ”“ CVE-2026-25823 - Critical (9.8) HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauth... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-25823/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-25823
Severity
Critical
CVSS Score
9.8
Type
buffer_overflow
Status
unconfirmed
EPSS
25.6%
Social Posts
1

CWE

  • CWE-121

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

25.6%Probability of exploitation in the next 30 days