VYPR

Vitogate 300

by Carrier

CVEs (4)

  • CVE-2025-9494HigSep 23, 2025
    risk 0.55cvss epss 0.01

    An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected installations. Specifically, the `/cgi-bin/vitogate.cgi` endpoint is affected, when the `form` JSON parameter is set to `form-0-2`. The…

  • CVE-2023-5222Sep 27, 2023
    risk 0.10cvss epss 0.75

    A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The…

  • CVE-2023-45852Oct 14, 2023
    risk 0.07cvss epss 0.14

    In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

  • CVE-2023-5702Oct 23, 2023
    risk 0.05cvss epss 0.15

    A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used.…