Sharp

Jh-rv11 Firmware

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 14.02.2024 10:15:08
  • Zuletzt bearbeitet 25.03.2025 17:15:50

Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.

  • EPSS 0.16%
  • Veröffentlicht 14.02.2024 10:15:08
  • Zuletzt bearbeitet 25.03.2025 17:15:50

Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displ...

  • EPSS 0.12%
  • Veröffentlicht 14.02.2024 10:15:08
  • Zuletzt bearbeitet 21.11.2024 08:58:23

Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.

  • EPSS 2.54%
  • Veröffentlicht 14.02.2024 10:15:08
  • Zuletzt bearbeitet 18.03.2025 14:15:38

Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is a...

  • EPSS 1.09%
  • Veröffentlicht 14.02.2024 10:15:08
  • Zuletzt bearbeitet 25.11.2024 18:54:34

Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

  • EPSS 0.31%
  • Veröffentlicht 14.02.2024 10:15:08
  • Zuletzt bearbeitet 19.03.2025 14:15:36

Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected produ...