VYPR
Vendor

Circontrol

Products
11
CVEs
11
Across products
22
Status
Private

Products

11

Recent CVEs

11
  • CVE-2018-12634CriJun 22, 2018
    risk 0.71cvss 9.8epss 0.57

    CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.

  • CVE-2020-8007CriNov 8, 2024
    risk 0.64cvss 9.8epss 0.02

    The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpserver1, and pingip.

  • CVE-2018-17922CriNov 2, 2018
    risk 0.64cvss 9.8epss 0.03

    Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.

  • CVE-2018-17918CriNov 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.

  • CVE-2018-16669CriSep 18, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the…

  • CVE-2020-8006HigApr 12, 2024
    risk 0.57cvss 8.8epss 0.01

    The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation…

  • CVE-2018-12635HigJun 22, 2018
    risk 0.49cvss 7.5epss 0.01

    CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.

  • CVE-2018-16672MedSep 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.

  • CVE-2018-16670MedSep 18, 2018
    risk 0.36cvss 5.3epss 0.25

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.

  • CVE-2018-16671MedSep 18, 2018
    risk 0.35cvss 5.3epss 0.09

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.

  • CVE-2018-16668MedSep 18, 2018
    risk 0.35cvss 5.3epss 0.10

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.