HarborGuard / CVE
Back to search
CRITICALCVE-2026-2248Published Modified CNA MHV

CVE-2026-2248: Unauthenticated Remote Root Shell Access via Web Console in METIS WIC

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compromise, allowing unauthorized access to modify system configuration, read sensitive data, or disrupt device operations

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
oscore 2.1.235-r19
Affected Products
1

Fix available

oscore 2.1.235-r19
Affected packages
  • METIS Cyberspace Technology SA / METIS WIC
    oscore 2.1.234-r18
    Fixed in oscore 2.1.235-r19
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H