CVE-2026-2250

HIGH

METIS WIC - Unauthenticated Sensitive Information Exposure via /dbviewer/ Endpoint

Title source: llm
STIX 2.1

Description

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 27.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-215 CWE-284
Status published
Products (2)
METIS Cyberspace Technology SA/METIS WIC oscore 2.1.234-r18
METIS Cyberspace Technology SA/METIS WIC oscore 2.1.235-r19
Published Feb 11, 2026
Tracked Since Feb 18, 2026