CVE-2026-2248 describes an unauthenticated web-based shell vulnerability in METIS WIC devices (versions <= oscore 2.1.234-r18) at the /console endpoint. This critical vulnerability (CVSS 9.8) allows a remote attacker to execute arbitrary operating system commands with root privileges, leading to full system compromise. While no public exploits or active exploitation have been observed, and community discussion is minimal, the ease of exploitation and severe impact warrant immediate attention for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| METIS Cyberspace Technology SA | METIS WIC | oscore 2.1.234-r18CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.