VYPR
Vendor

ESPEC

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2025-27845CriAug 14, 2025
    risk 0.64cvss 9.8epss 0.00

    In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.

  • CVE-2025-27847MedAug 14, 2025
    risk 0.28cvss 4.3epss 0.00

    In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.

  • CVE-2025-27846MedAug 14, 2025
    risk 0.28cvss 4.3epss 0.00

    In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.