A set of critical vulnerabilities has been identified in the METZ CONNECT EWIO2 series, including models EWIO2-M, EWIO2-M-BM, and EWIO2-BM running firmware versions below 2.2.0. The most severe issue is an authentication bypass (CVE-2025-41733/41734) that allows unauthenticated attackers with network access to gain administrative control over the device. Exploitation enables attackers to change configurations, manipulate data, disrupt services, and potentially render the device inoperable. Additional vulnerabilities include improper control of filename for include/require statements, unrestricted upload of dangerous file types, path traversal, and improper access control, collectively enabling remote code execution and full device compromise.
CISA has issued an ICS advisory (ICSA-25-322-05) highlighting the remote exploitability and low attack complexity of these flaws, assigning a CVSS v4 base score of 9.3. The vulnerabilities stem from the commissioning wizard failing to validate device initialization, allowing attackers to set root credentials via crafted POST requests. Organizations using affected METZ CONNECT EWIO2 devices are urged to review technical details and apply mitigations to prevent unauthorized access and maintain device integrity and availability.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
SecurityOnline reported that critical METZ CONNECT EWIO2 vulnerabilities, rated up to CVSS 9.8, could enable unauthenticated remote code execution and administrative takeover on industrial controllers.
CISA released ICS advisory ICSA-25-322-05 as part of a batch of six industrial control systems advisories, alerting organizations to vulnerabilities affecting METZ CONNECT EWIO2 products.
CERT VDE published advisory VDE-2025-097 for METZ CONNECT EWIO2 series, describing a Config API authentication bypass that could allow an attacker to gain administrative control of affected devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecertvde.com
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.