CVE-2026-2248Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compromise, allowing unauthorized access to modify system configuration, read sensitive data, or disrupt device operations

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-11: 3Technical Details · 2026-02-11: 302-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2248: CRITICAL] Critical security vulnerability in METIS WIC devices (&lt;= oscore 2.1.234-r18): Unauthenticated access via /console endpoint allows remote attackers to execute OS commands with root pri...#cve,CVE-2026-2248,#cybersecurity https://cvefind.com/CVE-2026-2248

    Post summary

    The post announces a critical CVE (CVE‑2026‑2248) affecting METIS WIC devices, highlighting unauthenticated remote code execution via the /console endpoint, without mentioning PoC, exploit tools, active exploitation, or patches.

    0000051
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2248 - Critical METIS WIC devices (versions &amp;lt;= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attack... https://www.thehackerwire.com/vulnerability/CVE-2026-2248/ https://t.co/2cdV1CTUDA

    Post summary

    The post discloses CVE‑2026‑2248 as a critical flaw in METIS WIC devices, where an unauthenticated web‑based shell at /console allows remote attackers to execute code.

    0000064
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2248 METIS WIC devices (versions &lt;= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allow… https://www.cve.org/CVERecord?id=CVE-2026-2248

    Post summary

    The post announces CVE‑2026‑2248, detailing a web‑based shell exposed on METIS WIC devices without authentication, highlighting a remote code execution vulnerability.

    00000347
    56.5K followersView on X

Explore more