CVE-2026-2250
HIGHMETIS WIC - Unauthenticated Sensitive Information Exposure via /dbviewer/ Endpoint
Title source: llmDescription
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.
References (2)
Core 2
Core References
Various Sources x_vendor-website
https://www.metis.tech/
Scores
CVSS v3
7.5
EPSS
0.0036
EPSS Percentile
27.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-215
CWE-284
Status
published
Products (2)
METIS Cyberspace Technology SA/METIS WIC
oscore 2.1.234-r18
METIS Cyberspace Technology SA/METIS WIC
oscore 2.1.235-r19
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026