CVE-2021-34592

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
27/04/2022
Last modified:
10/09/2022

Description

In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools