Back

HIGH

Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC

Published Feb 11, 2026

Description

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner MHV
Published Feb 11, 2026
Updated Feb 12, 2026
Reserved Feb 9, 2026

CISA Vulnrichment

Updated Feb 11, 2026

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner MHV
Published Feb 11, 2026
Updated Feb 12, 2026

GitHub

No data