Back to Database
Status published
Medium
CVE-2025-0432
HMS Networks Ewon Flexy 202 Cleartext Transmission of Sensitive Information
Vulnerability Description
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0432
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Khalid Markar, Parul Sindhwad and Dr. Faruk Kazi from CoE-CNDS Lab, VJTI, Mumbai, India reported this vulnerability to CISA
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-023-06
- https://www.hms-networks.com/cyber-security
- https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/ewon/manuals-and-guides---installation-guides/best-practices-for-a-secure-usage-of-the-ewon-solution-en.pdf?sfvrsn=37160847_4
- https://support.hms-networks.com/hc/en-us/articles/19393244940818-How-to-block-all-the-unused-Ewon-Flexy-Cosy131-services-on-the-LAN-WAN-and-or-VPN-interface
Affected Vendor
HMS Networks
View all reports →Affected Software
Ewon Flexy 202
Vulnerable Versions:
All
Timeline
Official Publish:
January 28th, 2025
Last Modified:
January 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N