The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
| Software | From | Fixed in |
|---|---|---|
| metz-connect / ewio2-m_firmware | - | 2.2.0 |
| metz-connect / ewio2-m-bm_firmware | - | 2.2.0 |
| metz-connect / ewio2-bm_firmware | - | 2.2.0 |