CVE-2026-2250

Published Feb 11, 2026

Last updated 3 months ago

Overview

Description
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.
Source
56a186b1-7f5e-4314-ba38-38d5499fccfd
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

56a186b1-7f5e-4314-ba38-38d5499fccfd
CWE-215

Social media

Hype score
Not currently trending