LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-25823

CVE-2026-25823 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 13, 2026

HMS Networks Ewon - Buffer Overflow

Published: March 13, 2026Updated: March 13, 2026Remote Exploitable

Overview

HMS Networks Ewon Flexy < 15.0s4, Cosy+ 22.xx < 22.1s6, and Cosy+ 23.xx < 23.0s3 contain a stack buffer overflow in firmware, letting unauthenticated remote attackers cause denial of service or execute code remotely, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unauthenticated attackers can cause denial of service or execute arbitrary code remotely, potentially compromising the device.

Mitigation

Update to firmware versions 15.0s4, 22.1s6, 23.0s3 or later.

Details

CVE ID
CVE-2026-25823
Severity
Critical
CVSS Score
9.8
Type
buffer_overflow
Status
new

CWE

  • CWE-121

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H