Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w46c-9jvj-8r29

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

EPSS

Процентиль: 10%
0.00203
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.8
nvd
12 месяцев назад

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

EPSS

Процентиль: 10%
0.00203
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-494