CVE 9.8 CRITICAL

Unauthenticated Remote Root Shell Access via Web Console in METIS WIC_CVE-2026-2248

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compromise, allowing unauthorized access to modify system configuration, read sensitive data, or disrupt device operations

AI Analysis

Unauthenticated remote root shell access via web console

Basic Information

ID CVE-2026-2248
Source MHV
Published Feb 11, 2026 at 14:15

Affected Product

Vendor METIS Cyberspace Technology SA
Product METIS WIC
Version oscore 2.1.234-r18
Affected Versions METIS Cyberspace Technology SA METIS WIC oscore 2.1.234-r18

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor METIS Cyberspace Technology SA
Product METIS WIC
Version oscore 2.1.234-r18

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.