HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter.
The vulnerability (CWE-315) consists of storing sensitive authentication data in session cookies with insufficient entropy of the encryption parameter. An attacker possessing an intercepted session cookie can perform a brute-force attack on that encryption parameter, which consequently allows the recovery of the logged-in user's password. The weak range of possible values for the encryption parameter makes the attack practically feasible without excessive computational resources.
An attacker can reproduce the user's password and gain full access to the device, threatening the confidentiality and integrity of configuration and data transmitted through the industrial gateway.
Device firmware must be updated to the following versions: Ewon Flexy — 15.0s4 or later; Cosy+ (branch 22.xx) — 22.1s6 or later; Cosy+ (branch 23.xx) — 23.0s3 or later. Details are available in the HMS Networks manufacturer security bulletin (HMS-Security-Advisory-2026-03-09-001).
HMS Networks Ewon Flexy with firmware prior to version 15.0s4; HMS Networks Cosy+ with firmware in branch 22.xx prior to version 22.1s6; HMS Networks Cosy+ with firmware in branch 23.xx prior to version 23.0s3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N