peter bassill · operator
$ cve CVE-2012-5863 JSON

CVE-2012-5863 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 24.8% (pctl 98)

Patch early

A public exploit exists.

Description

These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS24.82% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2012-11-23
Last modified2026-06-16

Affected (4)

VendorProduct
sinapsitechesolar duo photovoltaic system monitor
sinapsitechesolar light photovoltaic system monitor
sinapsitechesolar photovoltaic system monitor
sinapsitechsinapsi firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD