VendorsBINOM3universal_multifunctional_electric_power_quality_meter_firmwareall versions
Vulnerabilities

BINOM3 Universal Multifunctional Electric Power Quality Meter Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-5162
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configuration.
Published 2017-02-13 · Modified
10.0EPSS 0.126
CVE-2017-5166
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. An INFORMATION EXPOSURE flaw can be used to gain privileged access to the device.
Published 2017-02-13 · Modified
9.8EPSS 0.017
CVE-2017-5167
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.
Published 2017-02-13 · Modified
8.6EPSS 0.014
CVE-2017-5165
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.
Published 2017-02-13 · Modified
7.6EPSS 0.007
CVE-2017-5164
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary script code in another user's browser session (CROSS-SITE SCRIPTING).
Published 2017-02-13 · Modified
6.1EPSS 0.008