CVE-2024-33895: Hms-Networks Ewon Cosy+ Firmware

Medium severity, CVSS 6.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

Affected products

  • Hms-Networks Ewon Cosy+ Firmware: from 21.0, up to and including 21.2s10; from 22.0, up to and including 22.1s3

Published 2024-08-02. Last modified 2026-06-17.