VYPR

Solarview Compact Firmware

by Contec Co., Ltd.

CVEs (7)

  • CVE-2023-23333CriFeb 6, 2023
    risk 0.75cvss 9.8epss 0.99

    There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.

  • CVE-2022-40881CriNov 17, 2022
    risk 0.66cvss 9.8epss 0.29

    SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

  • CVE-2023-46509CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

  • CVE-2023-29919CriMay 23, 2023
    risk 0.64cvss 9.1epss 0.60

    SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

  • CVE-2022-44354CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.02

    SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.

  • CVE-2023-40924HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.03

    SolarView Compact < 6.00 is vulnerable to Directory Traversal.

  • CVE-2022-44355MedNov 29, 2022
    risk 0.40cvss 6.1epss 0.02

    SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.