VendorsElspec LTDg5dfrall versions
Vulnerabilities

Elspec LTD G5DFR (G5 Digital Fault Recorder)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2024-22080
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.
Published 2024-03-20 · Analyzed
9.8EPSS 0.008
CVE-2024-22081
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.
Published 2024-03-20 · Analyzed
9.8EPSS 0.008
CVE-2024-22078
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.
Published 2024-03-20 · Analyzed
8.8EPSS 0.006
CVE-2024-22079
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.
Published 2024-03-20 · Analyzed
7.5EPSS 0.010
CVE-2024-46602
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.
Published 2025-01-07 · Analyzed
7.5EPSS 0.007
CVE-2024-46603
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
Published 2025-01-07 · Analyzed
7.5EPSS 0.007
CVE-2024-46601
Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.
Published 2025-01-07 · Analyzed
7.5EPSS 0.007
CVE-2024-22082
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused be an attacker get a better understanding of the operating system.
Published 2024-03-20 · Analyzed
7.5EPSS 0.006
CVE-2024-22084
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.
Published 2024-03-20 · Analyzed
7.5EPSS 0.004
CVE-2025-59392
On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.
Published 2025-11-06 · Analyzed
6.8EPSS 0.002
CVE-2024-22083
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks.
Published 2024-03-20 · Analyzed
6.5EPSS 0.006
CVE-2024-22085
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.
Published 2024-03-20 · Analyzed
6.2EPSS 0.002
CVE-2024-22077
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.
Published 2024-03-20 · Analyzed
5.3EPSS 0.005