Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC
Published Feb 11, 2026
7.5
HIGHCVSS 3.1
EPSS 0.44%
Description
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.
Affected products
-
Affected
- oscore 2.1.234-r18
Unaffected
- oscore 2.1.235-r19
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| METIS Cyberspace Technology SA | Metis Wic | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://cydome.io/vulnerability-advisory-cve-2026-2250-unauthenticated-data-exfilteration-and-information-disclosure-in-metis-wic-wireless-intelligent-collector technical-description
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7030 Advisory
- https://www.metis.tech/ x_vendor-website
| Link | Providers | Tags |
|---|---|---|
| https://cydome.io/vulnerability-advisory-cve-2026-2250-unauthenticated-data-exfilteration-and-information-disclosure-in-metis-wic-wireless-intelligent-collector | technical-description | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7030 | Advisory | |
| https://www.metis.tech/ | x_vendor-website |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data