VDE
by VDE
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-41655 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2025 | An unauthenticated remote attacker can access a URL which causes the device to reboot. | ||
| CVE-2025-41731 | Hig | 0.48 | 7.4 | 0.00 | Nov 10, 2025 | A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a timely manner and thus gain root access to… | ||
| CVE-2024-25998 | Hig | 0.48 | 7.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. | ||
| CVE-2024-28750 | Hig | 0.47 | 7.2 | 0.01 | Jul 9, 2024 | A remote attacker with high privileges may use a deleting file function to inject OS commands. | ||
| CVE-2024-28748 | Hig | 0.47 | 7.2 | 0.01 | Jul 9, 2024 | A remote attacker with high privileges may use a reading file function to inject OS commands. | ||
| CVE-2024-41974 | Hig | 0.46 | 7.1 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication. | ||
| CVE-2024-5849 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2024 | An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. | ||
| CVE-2024-38502 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2024 | An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. | ||
| CVE-2024-28134 | Hig | 0.46 | 7.0 | 0.00 | May 14, 2024 | An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive… | ||
| CVE-2025-3705 | Med | 0.44 | 6.8 | 0.01 | Jul 7, 2025 | A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive. | ||
| CVE-2025-0101 | Med | 0.42 | 6.5 | 0.00 | Apr 16, 2025 | A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart. | ||
| CVE-2024-41972 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges. | ||
| CVE-2025-1985 | Med | 0.40 | 6.1 | 0.00 | May 26, 2025 | Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device. | ||
| CVE-2024-3913 | Med | 0.38 | 5.9 | 0.01 | Aug 13, 2024 | An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup. | ||
| CVE-2022-3738 | Med | 0.38 | 5.9 | 0.01 | Jan 19, 2023 | The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be… | ||
| CVE-2024-41970 | Med | 0.37 | 5.7 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources. | ||
| CVE-2024-7698 | Med | 0.37 | 5.7 | 0.00 | Sep 10, 2024 | A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks. | ||
| CVE-2023-49676 | Med | 0.36 | 5.5 | 0.00 | May 6, 2024 | An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability. | ||
| CVE-2024-12650 | Med | 0.35 | 5.4 | 0.00 | Mar 5, 2025 | An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications. | ||
| CVE-2024-41968 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS. |
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker can access a URL which causes the device to reboot.
- risk 0.48cvss 7.4epss 0.00
A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a timely manner and thus gain root access to…
- risk 0.48cvss 7.3epss 0.01
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
- risk 0.47cvss 7.2epss 0.01
A remote attacker with high privileges may use a deleting file function to inject OS commands.
- risk 0.47cvss 7.2epss 0.01
A remote attacker with high privileges may use a reading file function to inject OS commands.
- risk 0.46cvss 7.1epss 0.00
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
- risk 0.46cvss 7.1epss 0.00
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
- risk 0.46cvss 7.1epss 0.00
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
- risk 0.46cvss 7.0epss 0.00
An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive…
- risk 0.44cvss 6.8epss 0.01
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive.
- risk 0.42cvss 6.5epss 0.00
A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.
- risk 0.42cvss 6.5epss 0.01
A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.
- risk 0.40cvss 6.1epss 0.00
Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.
- risk 0.38cvss 5.9epss 0.01
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
- risk 0.38cvss 5.9epss 0.01
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be…
- risk 0.37cvss 5.7epss 0.00
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
- risk 0.37cvss 5.7epss 0.00
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
- risk 0.36cvss 5.5epss 0.00
An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.
- risk 0.35cvss 5.4epss 0.00
An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications.
- risk 0.35cvss 5.4epss 0.00
A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
Page 2 of 3