CVE-2023-31502
Published May 11, 2023Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php.
Vendor/product archive
2 CVEs tagged to apsystems / ecu-r — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php.
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone…