VYPR

Energy Management Controller with Cloud Services

by Sharp

CVEs (7)

  • CVE-2024-23786CriFeb 14, 2024
    risk 0.61cvss 9.3epss 0.01

    Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page…

  • CVE-2024-23789HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.

  • CVE-2024-23783HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.

  • CVE-2024-23788HigFeb 14, 2024
    risk 0.53cvss 8.1epss 0.01

    Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.

  • CVE-2024-23787MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

  • CVE-2024-23785MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.

  • CVE-2024-23784MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page…