Impact
SolarView Compact Schedule Settings feature allows a log‑in user to submit crafted input that is executed as an operating system command, enabling the operator to run arbitrary code on the device. The vulnerability directly compromises confidentiality, integrity, and availability by allowing an attacker to potentially gain full control score of 8.7 classifies the issue as high severity. The EPSS score of 1% indicates that the probability of exploitation is low but non‑zero, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires authenticated access, meaning any user that can log in may exploit it once credentials are obtained.
Affected Systems
Contec SolarView Compact models SV-CPT-MC310 and SV-CPT-MC310F are affected. The flaw resides in the web interface accessed after authentication, meaning any user who can log in may potentially exploit it.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires authenticated access crafted input to the schedule settings, resulting in arbitrary OS command execution. This enables remote code execution on the device, potentially allowing full system compromise.
OpenCVE Enrichment