Vulnerabilities
Vulnerable Software
Hms-Networks:  >> Ewon Cosy+ 4g Eu  Security Vulnerabilities
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
CVSS Score
9.1
EPSS Score
0.004
Published
2024-08-06
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
CVSS Score
7.2
EPSS Score
0.071
Published
2024-08-02
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
CVSS Score
7.5
EPSS Score
0.001
Published
2024-08-02
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-08-02
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.
CVSS Score
8.8
EPSS Score
0.004
Published
2024-08-02
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
CVSS Score
6.6
EPSS Score
0.001
Published
2024-08-02


Contact Us

Shodan ® - All rights reserved