Back to search
CVE-2012-5863
Published: Nov 23, 2012
Modified: Jul 8, 2025
PUBLISHED
Description
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
| Vendor | Product | Versions |
|---|---|---|
Sinapsi | eSolar | affected 0 - < 2.0.2870_xxx_2.2.12 |
Sinapsi | eSolar DUO | affected 0 - < 2.0.2870_xxx_2.2.12 |
Sinapsi | eSolar Light | affected 0 - < 2.0.2870_xxx_2.2.12 |
Weaknesses (CWE)
References
21273
exploit
x_refsource_EXPLOIT-DB
20120911 Multiple vulnerabilities in Ezylog photovoltaic management server
mailing-list
x_refsource_BUGTRAQ
sinapsi-default-password(80200)
vdb-entry
x_refsource_XF
http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now