9.8

CVE-2025-41734

Unauthenticated Local File Inclusion in php module

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Metz-connectEwio2-m Firmware Version < 2.2.0
   Metz-connectEwio2-m Version-
Metz-connectEwio2-m-bm Firmware Version < 2.2.0
   Metz-connectEwio2-m-bm Version-
Metz-connectEwio2-bm Firmware Version < 2.2.0
   Metz-connectEwio2-bm Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.362
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

https://certvde.com/de/advisories/VDE-2025-097
Third Party Advisory