HIGH🇵🇱 Wersja polska

CVE-2012-5863

CVSS 10.0v2.0pub. 2012-11-23upd. 2026-04-29

These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Sinapsitech Esolar Duo Photovoltaic System Monitor

    HW
    Sinapsitech
    all versions
  • Sinapsitech Esolar Light Photovoltaic System Monitor

    HW
    Sinapsitech
    all versions
  • Sinapsitech Esolar Photovoltaic System Monitor

    HW
    Sinapsitech
    all versions
  • Sinapsitech Sinapsi Firmware

    OS
    Sinapsitech
    ≤ 2.0.2870
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2012-5861HIGH7.8same product

These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL ta...

CVE-2012-5862HIGH10.0same product

These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passw...

CVE-2012-5864HIGH9.4same product

These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. ...