peter bassill · operator
$ cve CVE-2012-5862 JSON

CVE-2012-5862 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 12.1% (pctl 96)

Patch early

A public exploit exists.

Description

These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS12.08% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-259
On CISA KEVno
Public exploityes
Published2012-11-23
Last modified2026-06-16

Affected (4)

VendorProduct
sinapsitechesolar duo photovoltaic system monitor
sinapsitechesolar light photovoltaic system monitor
sinapsitechesolar photovoltaic system monitor
sinapsitechsinapsi firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD