A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.
| Software | From | Fixed in |
|---|---|---|
| metz-connect / ewio2-m_firmware | - | 2.2.0 |
| metz-connect / ewio2-m-bm_firmware | - | 2.2.0 |
| metz-connect / ewio2-bm_firmware | - | 2.2.0 |