HMS Networks manufactures industrial remote-access and connectivity devices, with a focused product portfolio centered on the Ewon Cosy family of cellular and ethernet gateways that enable secure machine-to-machine communication in operational technology environments. The vendor's vulnerability disclosures cluster around its Cosy gateway line across regional cellular variants and ethernet models, reflecting the embedded networking and protocol-handling demands of devices bridging IT and OT infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hms Networks over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33896HIGH Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in versio | Aug 2, 2024 | 7.2 | 33 | NO | YES |
CVE-2020-14498CRITICAL HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. | Aug 26, 2020 | 10.0 | 32 | NO | NO |
CVE-2024-33897CRITICAL A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was pat | Aug 6, 2024 | 9.1 | 26 | NO | NO |
CVE-2024-33894HIGH Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges. | Aug 2, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-33892HIGH Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. Th | Aug 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2021-33214MEDIUM In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of con | Jul 9, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-10633MEDIUM A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to i | Apr 8, 2020 | 6.1 | 21 | NO | NO |
CVE-2018-19694MEDIUM HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. | Mar 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-33895MEDIUM Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 2 | Aug 2, 2024 | 6.6 | 20 | NO | NO |
CVE-2024-33893MEDIUM Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed | Aug 2, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hms Networks.
Media articles that mention a CVE ID that affects a product developed by Hms Networks — matched by CVE ID, not by vendor name.