← Back

Ewon Cosy Firmware

ewon_cosy_firmware

Vendor: Hms Networks • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hms Networks
1Ewon Cosy Firmware
Nov 21, 2024
Aug 6, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on...Show more
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.Show less
1Hms Networks
1Ewon Cosy Firmware
Nov 4, 2025
Aug 2, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
1Hms Networks
1Ewon Cosy Firmware
Nov 4, 2025
Aug 2, 2024
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
1Hms Networks
1Ewon Cosy Firmware
Jun 20, 2025
Aug 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.
1Hms Networks
1Ewon Cosy Firmware
Nov 4, 2025
Aug 2, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
1Hms Networks
1Ewon Cosy Firmware
Nov 4, 2025
Aug 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s...Show more
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3Show less
1Hms Networks
2Ewon Cosy Firmware
Ewon Flexy Firmware
Nov 21, 2024
Sep 18, 2020
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource...Show more
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.Show less
1Hms Networks
2Ewon Cosy Firmware
Ewon Flexy Firmware
Nov 21, 2024
Apr 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device...Show more
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.Show less