VYPR

DFS

by METIS

CVEs (1)

  • CVE-2026-2249CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in…