Elspec-ltd
Elspec-ltd G5dfr Firmware: vulnerabilidades y CVE
Elspec-ltd G5dfr Firmware tiene 13 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-59392 | Media (6.8) | 0.21% | — | 6 nov 2025 | On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port. |
| CVE-2024-46603 | Alta (7.5) | 0.69% | — | 7 ene 2025 | An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload. |
| CVE-2024-46602 | Alta (7.5) | 0.69% | — | 7 ene 2025 | An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload. |
| CVE-2024-46601 | Alta (7.5) | 0.67% | — | 7 ene 2025 | Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow. |
| CVE-2024-22085 | Media (6.2) | 0.23% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable. |
| CVE-2024-22084 | Alta (7.5) | 0.39% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files. |
| CVE-2024-22083 | Media (6.5) | 0.55% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks. |
| CVE-2024-22082 | Alta (7.5) | 0.63% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused be an attacker get a better understanding of the… |
| CVE-2024-22081 | Crítica (9.8) | 0.78% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism. |
| CVE-2024-22080 | Crítica (9.8) | 0.78% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing. |
| CVE-2024-22079 | Alta (7.5) | 1.0% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism. |
| CVE-2024-22078 | Alta (8.8) | 0.64% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This… |
| CVE-2024-22077 | Media (5.3) | 0.48% | — | 20 mar 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.