Total
398612 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-41720 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified. | |||||
| CVE-2025-41719 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password. | |||||
| CVE-2025-41718 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI. | |||||
| CVE-2025-41717 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’). | |||||
| CVE-2025-41714 | 2026-06-17 | N/A | 8.8 HIGH | ||
| The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts outside the intended storage location. In certain configurations this enables arbitrary file write and may be leveraged to achieve remote code execution. | |||||
| CVE-2025-41713 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| During a short time frame while the device is booting an unauthenticated remote attacker can send traffic to unauthorized networks due to the switch operating in an undefined state until a CPU-induced reset allows proper configuration. | |||||
| CVE-2025-41712 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server. | |||||
| CVE-2025-41711 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access. | |||||
| CVE-2025-41710 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges. | |||||
| CVE-2025-41709 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. | |||||
| CVE-2025-41708 | 2026-06-17 | N/A | 7.4 HIGH | ||
| Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission. | |||||
| CVE-2025-41707 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue without affecting the core functionality. | |||||
| CVE-2025-41706 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET request with an over-long content-length to trigger the issue without affecting the core functionality. | |||||
| CVE-2025-41705 | 2026-06-17 | N/A | 6.8 MEDIUM | ||
| An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend. | |||||
| CVE-2025-41704 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality. | |||||
| CVE-2025-41703 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command. | |||||
| CVE-2025-41702 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key. | |||||
| CVE-2025-41701 | 2026-06-17 | N/A | 7.8 HIGH | ||
| An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context. | |||||
| CVE-2025-41700 | 1 Codesys | 1 Codesys | 2026-06-17 | N/A | 7.8 HIGH |
| An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context. | |||||
| CVE-2025-41699 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to improper control of generation of code ('Code Injection'). | |||||
