CVE-2016-2297: Meteocontrol Web'log Basic 100

Critical severity, CVSS 9.4. EPSS: 4.3% chance of exploitation in the next 30 days.

Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature."

Affected products

  • Meteocontrol Web'log Basic 100: affected versions not specified
  • Meteocontrol Web'log Light: affected versions not specified
  • Meteocontrol Web'log Pro: affected versions not specified
  • Meteocontrol Web'log Pro Unlimited: affected versions not specified

Published 2016-05-14. Last modified 2026-06-17.