Metz Connect's vulnerability footprint centers on its EWIO2 industrial I/O gateway product line and associated firmware, which are used in building automation and networked control systems. The observed disclosures cluster around this specialized embedded product family; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metz Connect over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41733CRITICAL The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root | Nov 18, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-41734CRITICAL An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices. | Nov 18, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-41736HIGH A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code executio | Nov 18, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-41735HIGH A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution. | Nov 18, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-41737HIGH Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules. | Nov 18, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metz Connect.
Media articles that mention a CVE ID that affects a product developed by Metz Connect — matched by CVE ID, not by vendor name.