Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
CVE-2024-33896
Score 7.2 from GitHub Security Advisory (severity: HIGH) published 2024-08-02. NVD baseline CVSS 7.2; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.2
- EG Score
- 7.2(medium)
- EG Risk
- 48(Track)EG Risk 48/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity72% × 45%Exploitation40% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 4%
- EPSS %ILE
- 90%
- KEV
- Not listed
Published
August 2, 2024
Last Modified
November 4, 2025
References (5)
- cve@mitrehttps://blog.syss.com/posts/hacking-a-secure-industrial-remote-access-gateway/
- cve@mitrehttps://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/cybersecurity/security-advisory/hms-security-advisory-2024-07-29-001--ewon-several-cosy--vulnerabilities.pdf
- cve@mitrehttps://www.ewon.biz/products/cosy/ewon-cosy-wifi
- cve@mitrehttps://www.hms-networks.com/cyber-security
- af854a3a-2127-422b-91ae-364da2661108http://seclists.org/fulldisclosure/2024/Aug/21
Related CVEs
Related CVEs are temporarily unavailable — the same-product, same-vendor and same-CWE lists could not be loaded just now. That is not a sign that none exist; please retry shortly.
Frequently asked(5)
What is CVE-2024-33896?
When was CVE-2024-33896 disclosed?
Is CVE-2024-33896 actively exploited?
What is the CVSS score of CVE-2024-33896?
How do I remediate CVE-2024-33896?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2024-33896
Is Your Infrastructure Affected by CVE-2024-33896?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.