CVE-2020-10633
Status: ModifiedMedium (6.1)—
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Base score: 6.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.69%
- Percentile among all scored CVEs: 51
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-79
- CWE-79
References
Raw JSON (NVD)
Show
{
"id": "CVE-2020-10633",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "n/a",
"product": "eWON Flexy and Cosy",
"versions": [
{
"status": "affected",
"version": "All firmware versions prior to 14.1s0"
}
]
}
]
}
],
"published": "2020-04-08T01:15:11.953",
"references": [
{
"url": "https://www.us-cert.gov/ics/advisories/icsa-20-098-03",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.us-cert.gov/ics/advisories/icsa-20-098-03",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de tipo XSS (cross-site scripting) no persistente en eWON Flexy y Cozy (todas las versiones de firmware anteriores a 14.1s0). Un atacante podría enviar una URL especialmente diseñada para iniciar un cambio de contraseña para el dispositivo. El objetivo debe introducir las credenciales en la puerta de enlace antes de que el ataque pueda tener éxito."
}
],
"lastModified": "2026-06-17T02:48:08.233",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hms-networks:ewon_flexy_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88BD00FA-3A80-43B5-B355-52D6DF51D4A7",
"versionEndExcluding": "14.1s0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hms-networks:ewon_flexy:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "58057056-ED41-4C3F-9ABC-DB595741C9A0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hms-networks:ewon_cosy_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "597AE513-66CE-4544-AA5E-4B9D99E3F1B8",
"versionEndExcluding": "14.1s0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hms-networks:ewon_cosy:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "999DB8E0-FE32-4561-A8E8-E95B8574419B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}