CVE-2024-33897: Hms-Networks Ewon Cosy+ Firmware

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

Affected products

  • Hms-Networks Ewon Cosy+ Firmware: from 21.0s0, before 21.2s10 (fixed in 21.2s10); from 22.0s0, before 22.1s3 (fixed in 22.1s3)

Published 2024-08-06. Last modified 2026-06-17.