CVE-2025-41735

8.8

METZ CONNECT · Energy-Controlling EWIO2-M, Energy-Controlling EWIO2-M-BM, Ethernet-IO EWIO2-BM

A low privileged remote attacker can perform arbitrary file uploads, leading to remote code execution due to a lack of file validation.

Executive summary

A critical remote code execution vulnerability in METZ CONNECT devices allows authenticated attackers to upload malicious files to arbitrary locations.

Vulnerability

This vulnerability is classified as CWE-434, representing an unrestricted upload of files with dangerous types. The flaw exists because the application fails to perform necessary file type and path validation, allowing an authenticated user with low privileges to upload files to unauthorized locations and achieve remote code execution.

Business impact

The ability for an attacker to execute arbitrary code on these industrial control components presents a severe risk to operational integrity. A successful exploit could result in full system compromise, unauthorized access to sensitive operational data, and potential disruption of industrial processes, justifying the high CVSS score of 8.8.

Remediation

Immediate Action: Update the affected METZ CONNECT firmware to version 2.2.0 or later as specified by the vendor advisory.

Proactive Monitoring: Review system access logs for unusual file upload activity or unexpected file creation events in directories not intended for user-supplied content.

Compensating Controls: Restrict network access to the affected devices by placing them behind a firewall and limiting management interface access to trusted administrative subnets only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system takeover, administrators should prioritize updating these industrial components to version 2.2.0 immediately. If patching is not immediately feasible, ensure that all access to the management interfaces of these devices is strictly segmented from the broader network to minimize the risk of unauthorized access.

Sources

Originally found and disclosed by Noam Moshe from Claroty Team82, Tomer Goldschmidt from Claroty Team82, per the CVE Program record.