A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.
| Software | From | Fixed in |
|---|---|---|
| metz-connect / ewio2-m_firmware | - | 2.2.0 |
| metz-connect / ewio2-m-bm_firmware | - | 2.2.0 |
| metz-connect / ewio2-bm_firmware | - | 2.2.0 |