peter bassill · operator
$ cve CVE-2012-5864 JSON

CVE-2012-5864 EXPLOIT

9.4
HIGH · CVSS 2.0 · EPSS 4.9% (pctl 92)

Patch early

A public exploit exists.

Description

These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.

Scoring

CVSS9.4 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
EPSS4.91% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2012-11-23
Last modified2026-06-16

Affected (4)

VendorProduct
sinapsitechesolar duo photovoltaic system monitor
sinapsitechesolar light photovoltaic system monitor
sinapsitechesolar photovoltaic system monitor
sinapsitechsinapsi firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD