
CVE-2026-2250 The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database conta… https://www.cve.org/CVERecord?id=CVE-2026-2250
Post summary
CVE-2026-2250 exposes an unauthenticated /dbviewer/ endpoint on METIS WIC devices, enabling remote attackers to export the internal telemetry SQLite database. No PoC, exploit code, patch, or active exploitation evidence is mentioned.

