CVE-2026-25819 is a high-severity Denial of Service vulnerability affecting HMS Networks Ewon Flexy (firmware before 15.0s4) and Cosy+ (firmware 22.xx before 22.1s6, and 23.xx before 23.0s3) devices. An unauthenticated attacker with network access to the device's GUI can trigger a system reboot by sending a specially crafted HTTP request. Rated with a CVSS score of 7.5 (High), this vulnerability has a network attack vector and low attack complexity, leading to a complete loss of availability without requiring any privileges or user interaction. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.