METZ CONNECT EWIO2 Series Authentication Bypass Vulnerability Allowing Unauthenticated Admin Takeover

Vulnerability

A critical authentication bypass vulnerability has been identified in the METZ CONNECT EWIO2 series, specifically in the Energy-Controlling EWIO2-M, EWIO2-M-BM, and Ethernet-IO EWIO2-BM models, all running firmware prior to 2.2.0. This vulnerability allows unauthenticated remote attackers with network access to gain administrative control over the affected devices. Once compromised, attackers can execute arbitrary PHP files, change configurations, manipulate data, disrupt services, and potentially render the device non-functional.

Impact

Exploitation of this vulnerability allows for unauthorized administrative access, enabling attackers to take full control of the device. This could lead to unauthorized changes in configuration, data manipulation, service disruption, or causing the device to become non-functional.

Remediation

Users are advised to update to version 2.2.0 or later. Schedule the update during the next maintenance window, as no workaround provides equivalent protection.

Added: Nov 18, 2025, 11:19 AM
Updated: Nov 18, 2025, 2:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.