← All CVEs

CVE-2012-5863

high · 10

These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.

10
CVSS
24.8%
EPSS (exploit prob.)
98th
EPSS percentile
2012-11-23
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-78CWE-264

Affected products

VendorProductAffected versions
sinapsitechsinapsi_firmware<= 2.0.2870
sinapsitechesolar_duo_photovoltaic_system_monitorall versions
sinapsitechesolar_light_photovoltaic_system_monitorall versions
sinapsitechesolar_photovoltaic_system_monitorall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-5863