Vendor CVEs
VDE
All CVEs
48 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6596 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | ||
| CVE-2024-6422 | Cri | 0.64 | 9.8 | 0.01 | Jul 10, 2024 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. | ||
| CVE-2024-25995 | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation. | ||
| CVE-2023-4149 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2023 | A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based… | ||
| CVE-2022-45140 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. | ||
| CVE-2022-45138 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full… | ||
| CVE-2024-28751 | Cri | 0.59 | 9.1 | 0.01 | Jul 9, 2024 | An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. | ||
| CVE-2024-7699 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data. | ||
| CVE-2024-43388 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. | ||
| CVE-2015-10123 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2024 | An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device. | ||
| CVE-2024-26288 | Hig | 0.57 | 8.7 | 0.00 | Mar 12, 2024 | An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected. | ||
| CVE-2023-6357 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2023 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | ||
| CVE-2024-25999 | Hig | 0.55 | 8.4 | 0.00 | Mar 12, 2024 | An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. | ||
| CVE-2025-41654 | Hig | 0.53 | 8.2 | 0.00 | May 26, 2025 | An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog. | ||
| CVE-2024-41973 | Hig | 0.53 | 8.1 | 0.01 | Nov 18, 2024 | A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges. | ||
| CVE-2024-41971 | Hig | 0.53 | 8.1 | 0.01 | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss. | ||
| CVE-2024-41967 | Hig | 0.53 | 8.1 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack. | ||
| CVE-2024-28136 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service. | ||
| CVE-2023-49675 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability. | ||
| CVE-2025-41689 | Hig | 0.49 | 7.5 | 0.00 | Aug 19, 2025 | An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data. | ||
| CVE-2024-8419 | Hig | 0.49 | 7.5 | 0.00 | Jun 30, 2025 | The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication. | ||
| CVE-2025-41655 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2025 | An unauthenticated remote attacker can access a URL which causes the device to reboot. | ||
| CVE-2025-41731 | Hig | 0.48 | 7.4 | 0.00 | Nov 10, 2025 | A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a timely manner and thus gain root access to… | ||
| CVE-2024-25998 | Hig | 0.48 | 7.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. | ||
| CVE-2024-28750 | Hig | 0.47 | 7.2 | 0.01 | Jul 9, 2024 | A remote attacker with high privileges may use a deleting file function to inject OS commands. | ||
| CVE-2024-28748 | Hig | 0.47 | 7.2 | 0.01 | Jul 9, 2024 | A remote attacker with high privileges may use a reading file function to inject OS commands. | ||
| CVE-2024-41974 | Hig | 0.46 | 7.1 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication. | ||
| CVE-2024-5849 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2024 | An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. | ||
| CVE-2024-38502 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2024 | An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. | ||
| CVE-2024-28134 | Hig | 0.46 | 7.0 | 0.00 | May 14, 2024 | An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive… | ||
| CVE-2025-3705 | Med | 0.44 | 6.8 | 0.01 | Jul 7, 2025 | A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive. | ||
| CVE-2025-0101 | Med | 0.42 | 6.5 | 0.00 | Apr 16, 2025 | A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart. | ||
| CVE-2024-41972 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges. | ||
| CVE-2025-1985 | Med | 0.40 | 6.1 | 0.00 | May 26, 2025 | Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device. | ||
| CVE-2024-3913 | Med | 0.38 | 5.9 | 0.01 | Aug 13, 2024 | An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup. | ||
| CVE-2022-3738 | Med | 0.38 | 5.9 | 0.01 | Jan 19, 2023 | The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be… | ||
| CVE-2024-41970 | Med | 0.37 | 5.7 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources. | ||
| CVE-2024-7698 | Med | 0.37 | 5.7 | 0.00 | Sep 10, 2024 | A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks. | ||
| CVE-2023-49676 | Med | 0.36 | 5.5 | 0.00 | May 6, 2024 | An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability. | ||
| CVE-2024-12650 | Med | 0.35 | 5.4 | 0.00 | Mar 5, 2025 | An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications. | ||
| CVE-2024-41968 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS. | ||
| CVE-2018-25090 | Med | 0.35 | 5.4 | 0.00 | Mar 13, 2024 | An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability. | ||
| CVE-2024-25997 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected. | ||
| CVE-2024-25994 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only. | ||
| CVE-2024-7734 | Med | 0.34 | 5.3 | 0.00 | Sep 10, 2024 | An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers. | ||
| CVE-2024-25996 | Med | 0.34 | 5.3 | 0.00 | Mar 12, 2024 | An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user. | ||
| CVE-2022-45139 | Med | 0.34 | 5.3 | 0.00 | Feb 27, 2023 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a… | ||
| CVE-2024-28135 | Med | 0.33 | 5.0 | 0.01 | May 14, 2024 | A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected. |
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based…
- risk 0.64cvss 9.8epss 0.01
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
- risk 0.64cvss 9.8epss 0.01
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full…
- risk 0.59cvss 9.1epss 0.01
An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
- risk 0.57cvss 8.8epss 0.01
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
- risk 0.57cvss 8.8epss 0.01
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
- risk 0.57cvss 8.8epss 0.01
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.
- risk 0.57cvss 8.7epss 0.00
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
- risk 0.57cvss 8.8epss 0.01
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
- risk 0.53cvss 8.2epss 0.00
An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog.
- risk 0.53cvss 8.1epss 0.01
A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.
- risk 0.53cvss 8.1epss 0.01
A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
- risk 0.53cvss 8.1epss 0.00
A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.
- risk 0.51cvss 7.8epss 0.01
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.
- risk 0.51cvss 7.8epss 0.00
An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data.
- risk 0.49cvss 7.5epss 0.00
The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker can access a URL which causes the device to reboot.
- risk 0.48cvss 7.4epss 0.00
A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a timely manner and thus gain root access to…
- risk 0.48cvss 7.3epss 0.01
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
- risk 0.47cvss 7.2epss 0.01
A remote attacker with high privileges may use a deleting file function to inject OS commands.
- risk 0.47cvss 7.2epss 0.01
A remote attacker with high privileges may use a reading file function to inject OS commands.
- risk 0.46cvss 7.1epss 0.00
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
- risk 0.46cvss 7.1epss 0.00
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
- risk 0.46cvss 7.1epss 0.00
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
- risk 0.46cvss 7.0epss 0.00
An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive…
- risk 0.44cvss 6.8epss 0.01
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive.
- risk 0.42cvss 6.5epss 0.00
A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.
- risk 0.42cvss 6.5epss 0.01
A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.
- risk 0.40cvss 6.1epss 0.00
Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.
- risk 0.38cvss 5.9epss 0.01
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
- risk 0.38cvss 5.9epss 0.01
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be…
- risk 0.37cvss 5.7epss 0.00
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
- risk 0.37cvss 5.7epss 0.00
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
- risk 0.36cvss 5.5epss 0.00
An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.
- risk 0.35cvss 5.4epss 0.00
An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications.
- risk 0.35cvss 5.4epss 0.00
A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
- risk 0.35cvss 5.4epss 0.00
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
- risk 0.34cvss 5.3epss 0.00
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a…
- risk 0.33cvss 5.0epss 0.01
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.