


Perceptive Security
SOC/SIEM Consultancy

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer ov…
Published:
12 maart 2026 om 23:00:00
Alert date:
13 maart 2026 om 20:06:20
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Critical Infrastructure
HMS Networks Ewon Flexy and Cosy+ devices contain a critical stack buffer overflow vulnerability that can lead to denial of service and unauthenticated remote code execution. The vulnerability affects Ewon Flexy firmware before version 15.0s4, Cosy+ firmware 22.xx before 22.1s6, and Cosy+ firmware 23.xx before 23.0s3. This represents a high-severity security flaw in industrial networking equipment that could allow attackers to gain unauthorized control of affected systems without authentication.
Technical details
Mitigation steps:
Affected products:
HMS Networks Ewon Flexy
HMS Networks Cosy+
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-25823
https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/cybersecurity/security-advisory/hms-security-advisory-2026-03-09-001---ewon-several-flexy-and-cosy--vulnerabilities.pdf?sfvrsn=f7c027b8_13
https://www.hms-networks.com/p/flexy20500-00ma-ewon-flexy-205
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
