VYPR

Vitogate 300

by Vitogate

CVEs (2)

  • CVE-2023-45852CriOct 14, 2023
    risk 0.65cvss 9.8epss 0.14

    In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

  • CVE-2025-9494HigSep 23, 2025
    risk 0.55cvss epss 0.01

    An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected installations. Specifically, the `/cgi-bin/vitogate.cgi` endpoint is affected, when the `form` JSON parameter is set to `form-0-2`. The…