CVE-2024-33894: Hms-Networks Ewon Cosy+ Firmware

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

Affected products

  • Hms-Networks Ewon Cosy+ Firmware: from 21.0s0, before 21.2s10 (fixed in 21.2s10); from 22.0s0, before 22.1s3 (fixed in 22.1s3)

Published 2024-08-02. Last modified 2026-06-17.