HMS Networks eWON Flexy and Cosy
A reflected cross-site scripting (XSS) vulnerability in HMS Networks eWON Cosy and eWON Flexy devices allows an attacker to initiate an administrator password change if an authenticated user clicks a malicious link. Successful exploitation could lock legitimate operators out of the device, preventing access to monitoring and control functions. The vulnerability affects all firmware versions prior to 14.1s0. No known public exploits exist, and exploitation requires high technical skill and user interaction.
- Network reachability to the eWON device (port 80 or 443)
- An authenticated administrator using a web browser
- Administrator must click a malicious link or visit a crafted web page
- Requires high technical skill to construct and deliver the attack
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ab9ba5d6-d798-4aca-8c74-d285b0eae3a6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.