Vulnerabilities
52 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-34081 +1 in the same advisory: …34080 | The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacke The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7.7. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2023-46509 | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-40924 | SolarView Compact < 6.00 is vulnerable to Directory Traversal. SolarView Compact < 6.00 is vulnerable to Directory Traversal. NVD description · AI analysis pending | 7.5 | 3% | PoC |
| — | |
| CVE-2023-28657 | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed may gain an administrative privilege. As a result, information regarding the product may be obtained and/or altered by the user. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2023-2758 | A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2023-2924 | A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functionality of the file /admin/reportupload.aspx. The manipulation of the argument files[] leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-230078 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 9.8 | 24% | PoC |
| — | |
| CVE-2023-27521 | OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command. NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2023-29919 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. NVD description · AI analysis pending | 9.1 | 60% | PoC |
| — | |
| CVE-2023-27917 | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute a OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the firmware Ver.3.7.10 and earlier (CPS-MG341-ADSC1-111, CPS-MG341-ADSC1-931, CPS-MG341G-ADSC1-111, CPS-MG341G-ADSC1-930, and CPS-MG341G5-ADSC1-931), M2M Controller Integrated Type with firmware Ver.3.7.6 and earlier versions (CPS-MC341-ADSC1-111, CPS-MC341-ADSC1-931, CPS-MC341-ADSC2-111, CPS-MC341G-ADSC1-110, CPS-MC341Q-ADSC1-111, CPS-MC341-DS1-111, CPS-MC341-DS11-111, CPS-MC341-DS2-911, and CPS-MC341-A1-111), and M2M Controller Configurable Type with firmware Ver.3.8.8 and earlier versions (CPS-MCS341-DS1-111, CPS-MCS341-DS1-131, CPS-MCS341G-DS1-130, CPS-MCS341G5-DS1-130, and CPS-MCS341Q-DS1-131). NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2023-23333 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through download There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. NVD description · AI analysis pending | 9.8 | 99% | PoC |
| — | |
| CVE-2023-22324 | SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2023-22339 | Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product. NVD description · AI analysis pending | 7.5 group max | 1% |
| — | ||
| CVE-2022-44456 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. NVD description · AI analysis pending | 9.8 | 70% |
| — | ||
| CVE-2022-44354 +1 in the same advisory: …44355 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2022-40881 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php NVD description · AI analysis pending | 9.8 | 30% | PoC |
| — | |
| CVE-2022-36159 +1 in the same advisory: …36158 | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2022-38100 | The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2022-35239 | The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verificat The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2022-31374 +1 in the same advisory: …31373 | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file. An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2022-29303 | Unauthenticated Command Injection in Contec SolarView Compact CVE-2022-29303 is an unauthenticated OS command injection flaw (CWE-78) in Contec SolarView Compact version 6.00, reachable through the conf_mail.php script. Because the CVSS vector requires no privileges and no user interaction over the network, a remote attacker can send crafted input to the vulnerable script and have it executed as operating system commands. Successful exploitation yields remote code execution on the device with the privileges of the web service, which attackers can leverage to recruit exposed monitors into Mirai-style IoT botnets or as a foothold into energy-sector networks. Affected organizations are operators of internet-facing SolarView Compact (SV-CPT-MC310 firmware) solar power monitoring systems. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-13, carries a 98% EPSS probability of exploitation within 30 days, and public reporting describes attacks threatening hundreds of solar power stations. Do: Apply Contec's updates per vendor instructions (CISA's required action), or discontinue use of the product if updates are unavailable; the affected release in the data is SolarView Compact 6.00, so update to any vendor-provided fixed release. Limit or remove internet exposure of the SolarView web interface and review access logs for unsolicited requests to conf_mail.php. Defenders should also watch for signs of IoT botnet compromise, as this flaw is among those used in Mirai campaigns. | 9.8 | 98% | KEV PoC ×2 |
| nichehundreds of internet-exposed solar power stations/monitoring systems | |
| CVE-2022-29298 +1 in the same advisory: …29302 | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. NVD description · AI analysis pending | 7.5 group max | 47% | PoC ×2 |
| — | |
| CVE-2021-20658 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors. SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors. NVD description · AI analysis pending | 9.8 group max | 4% |
| — |