In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.vde.com/en/advisories/VDE-2021-047 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2022-04-27T15:15:34.774811Z
Updated: 2024-09-17T01:46:57.289Z
Reserved: 2021-06-10T00:00:00
Link: CVE-2021-34602
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-04-27T16:15:11.267
Modified: 2024-11-21T06:10:47.783
Link: CVE-2021-34602
Redhat
No data.