Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w46c-9jvj-8r29

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

EPSS

Процентиль: 4%
0.00019
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.8
nvd
6 месяцев назад

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

EPSS

Процентиль: 4%
0.00019
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-494