CVE-2026-2249Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in the compromise of the software, granting unauthorized access to modify configuration, read and alter sensitive data, or disrupt services.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-11: 3Technical Details · 2026-02-11: 302-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2249: CRITICAL] Critical security vulnerability in METIS DFS devices &lt;= oscore 2.1.234-r18 exposes an unauthenticated web shell, allowing attackers to run OS commands with high privileges remotely.#cve,CVE-2026-2249,#cybersecurity https://cvefind.com/CVE-2026-2249

    Post summary

    Critical vulnerability CVE‑2026‑2249 in METIS DFS devices enables unauthenticated remote web shell with high‑privilege command execution.

    0000051
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-2249 - Critical METIS DFS devices (versions &amp;lt;= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attack... https://www.thehackerwire.com/vulnerability/CVE-2026-2249/ https://t.co/krqtQbpbLz

    Post summary

    The tweet highlights CVE‑2026‑2249 as a critical flaw in METIS DFS devices, exposing an unauthenticated web shell via the /console endpoint, but it provides no exploit code, patch info, or evidence of active attacks.

    0000068
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2249 METIS DFS devices (versions &lt;= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allow… https://www.cve.org/CVERecord?id=CVE-2026-2249

    Post summary

    CVE‑2026‑2249 exposes an unauthenticated web shell via the /console endpoint on affected METIS DFS devices.

    00000356
    56.5K followersView on X

Explore more