CVE-2025-5873
Estado: AplazadaBaja (2.1)—
A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php of the component Web UI. Performing a manipulation of the argument media results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-284, CWE-434
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-5873",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-5873",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-09T17:47:53.089620Z"
}
}
],
"cvssMetricV2": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.1,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "PROOF_OF_CONCEPT",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "LOW",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "cna@vuldb.com",
"affectedData": [
{
"vendor": "eCharge Hardy Barth",
"modules": [
"Web UI"
],
"product": "Salia PLCC",
"versions": [
{
"status": "affected",
"version": "2.3.0"
},
{
"status": "affected",
"version": "2.3.1"
},
{
"status": "affected",
"version": "2.3.2"
},
{
"status": "affected",
"version": "2.3.3"
},
{
"status": "affected",
"version": "2.3.4"
},
{
"status": "affected",
"version": "2.3.5"
},
{
"status": "affected",
"version": "2.3.6"
},
{
"status": "affected",
"version": "2.3.7"
},
{
"status": "affected",
"version": "2.3.8"
},
{
"status": "affected",
"version": "2.3.9"
},
{
"status": "affected",
"version": "2.3.10"
},
{
"status": "affected",
"version": "2.3.11"
},
{
"status": "affected",
"version": "2.3.12"
},
{
"status": "affected",
"version": "2.3.13"
},
{
"status": "affected",
"version": "2.3.14"
},
{
"status": "affected",
"version": "2.3.15"
},
{
"status": "affected",
"version": "2.3.16"
},
{
"status": "affected",
"version": "2.3.17"
},
{
"status": "affected",
"version": "2.3.18"
},
{
"status": "affected",
"version": "2.3.19"
},
{
"status": "affected",
"version": "2.3.20"
},
{
"status": "affected",
"version": "2.3.21"
},
{
"status": "affected",
"version": "2.3.22"
},
{
"status": "affected",
"version": "2.3.23"
},
{
"status": "affected",
"version": "2.3.24"
},
{
"status": "affected",
"version": "2.3.25"
},
{
"status": "affected",
"version": "2.3.26"
},
{
"status": "affected",
"version": "2.3.27"
},
{
"status": "affected",
"version": "2.3.28"
},
{
"status": "affected",
"version": "2.3.29"
},
{
"status": "affected",
"version": "2.3.30"
},
{
"status": "affected",
"version": "2.3.31"
},
{
"status": "affected",
"version": "2.3.32"
},
{
"status": "affected",
"version": "2.3.33"
},
{
"status": "affected",
"version": "2.3.34"
},
{
"status": "affected",
"version": "2.3.35"
},
{
"status": "affected",
"version": "2.3.36"
},
{
"status": "affected",
"version": "2.3.37"
},
{
"status": "affected",
"version": "2.3.38"
},
{
"status": "affected",
"version": "2.3.39"
},
{
"status": "affected",
"version": "2.3.40"
},
{
"status": "affected",
"version": "2.3.41"
},
{
"status": "affected",
"version": "2.3.42"
},
{
"status": "affected",
"version": "2.3.43"
},
{
"status": "affected",
"version": "2.3.44"
},
{
"status": "affected",
"version": "2.3.45"
},
{
"status": "affected",
"version": "2.3.46"
},
{
"status": "affected",
"version": "2.3.47"
},
{
"status": "affected",
"version": "2.3.48"
},
{
"status": "affected",
"version": "2.3.49"
},
{
"status": "affected",
"version": "2.3.50"
},
{
"status": "affected",
"version": "2.3.51"
},
{
"status": "affected",
"version": "2.3.52"
},
{
"status": "affected",
"version": "2.3.53"
},
{
"status": "affected",
"version": "2.3.54"
},
{
"status": "affected",
"version": "2.3.55"
},
{
"status": "affected",
"version": "2.3.56"
},
{
"status": "affected",
"version": "2.3.57"
},
{
"status": "affected",
"version": "2.3.58"
},
{
"status": "affected",
"version": "2.3.59"
},
{
"status": "affected",
"version": "2.3.60"
},
{
"status": "affected",
"version": "2.3.61"
},
{
"status": "affected",
"version": "2.3.62"
},
{
"status": "affected",
"version": "2.3.63"
},
{
"status": "affected",
"version": "2.3.64"
},
{
"status": "affected",
"version": "2.3.65"
},
{
"status": "affected",
"version": "2.3.66"
},
{
"status": "affected",
"version": "2.3.67"
},
{
"status": "affected",
"version": "2.3.68"
},
{
"status": "affected",
"version": "2.3.69"
},
{
"status": "affected",
"version": "2.3.70"
},
{
"status": "affected",
"version": "2.3.71"
},
{
"status": "affected",
"version": "2.3.72"
},
{
"status": "affected",
"version": "2.3.73"
},
{
"status": "affected",
"version": "2.3.74"
},
{
"status": "affected",
"version": "2.3.75"
},
{
"status": "affected",
"version": "2.3.76"
},
{
"status": "affected",
"version": "2.3.77"
},
{
"status": "affected",
"version": "2.3.78"
},
{
"status": "affected",
"version": "2.3.79"
},
{
"status": "affected",
"version": "2.3.80"
},
{
"status": "affected",
"version": "2.3.81"
}
]
}
]
}
],
"published": "2025-06-09T11:15:22.240",
"references": [
{
"url": "https://github.com/YZS17/CVE/blob/main/Salia_PLCC/Salia_PLCC_Slave_v2.2.0_File_Upload.md",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.311632",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.311632",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.585733",
"source": "cna@vuldb.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
},
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php of the component Web UI. Performing a manipulation of the argument media results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
},
{
"lang": "es",
"value": "Se encontró una vulnerabilidad en eCharge Hardy Barth Salia PLCC 2.2.0. Se ha declarado crítica. Esta vulnerabilidad afecta al código desconocido del archivo /firmware.php del componente Web UI. La manipulación del argumento \"media\" permite la carga sin restricciones. El ataque puede iniciarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió."
}
],
"lastModified": "2026-06-17T09:48:55.697",
"sourceIdentifier": "cna@vuldb.com"
}