CVE-2026-25817General

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provided the attacker has credentials.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-13); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-13: 2Mentions · 2026-03-14: 1PoC Mentioned / Linked · 2026-03-14: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 103-1303-14
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-132
General1Patch1
2026-03-141
Disclosure1
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25817 - High HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used... https://www.thehackerwire.com/vulnerability/CVE-2026-25817/ https://t.co/Y20zSNbmXe

    Post summary

    A new vulnerability (CVE-2026-25817) affecting multiple HMS Networks firmware versions is disclosed, noting improper neutralization of special elements, with no PoC, exploit, or patch details supplied in the tweet.

    0000047
    135 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25817: HIGH] Critical cyber security issue found in HMS Networks Ewon Flexy & Cosy+ devices. Attackers with low privilege access can execute remote code. Update firmware to latest versions!#cve,CVE-2026-25817,#cybersecurity https://cvefind.com/CVE-2026-25817

    Post summary

    A high‑severity remote code execution vulnerability (CVE‑2026‑25817) affects HMS Networks Ewon Flexy & Cosy+ devices; users are advised to upgrade firmware to mitigate the flaw.

    0000036
    602 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25817 HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization… https://www.cve.org/CVERecord?id=CVE-2026-25817

    Post summary

    The statement references CVE-2026-25817 and lists affected firmware versions, but provides no proof‑of‑concept, exploit code, patch details, or active exploitation evidence.

    00000158
    56.7K followersView on X

Explore more