VendorsFranklin Fuelingts-550_evoall versions
Vulnerabilities

Franklin Fueling franklinfueling TS-550 evo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2013-7248
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gain root privileges, as demonstrated using a cmdWebCheckRole action in a TSA_REQUEST.
Published 2014-01-26 · Modified
10.01 PoCEPSS 0.038
CVE-2023-5846
Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550
Published 2023-11-02 · Modified
9.8EPSS 0.003
CVE-2017-6565
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload.
Published 2017-05-01 · Modified
8.8EPSS 0.010
CVE-2021-46421
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
Published 2022-04-27 · Modified
7.5EPSS 0.060
CVE-2021-46420
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
Published 2022-04-27 · Modified
7.5EPSS 0.057
CVE-2017-6564
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.
Published 2017-05-01 · Modified
6.5EPSS 0.008
CVE-2013-7247
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user names and password hashes) via the cmdWebGetConfiguration action in a TSA_REQUEST.
Published 2014-01-26 · Modified
5.01 PoCEPSS 0.026