CVE-2012-6428

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
23/12/2012
Last modified:
01/07/2025

Description

The Carlo Gavazzi <br /> EOS-Box<br /> <br /> stores hard-coded passwords in the PHP file of <br /> the device. By using the hard-coded passwords, attackers can log into <br /> the device with administrative privileges. This could allow the attacker<br /> to have unauthorized access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:carlosgavazzi:eos-box_photovoltaic_monitoring_system_firmware:*:*:*:*:*:*:*:* 1.0.0 (including)
cpe:2.3:h:carlosgavazzi:eos-box_photovoltaic_monitoring_system:-:*:*:*:*:*:*:*