CVE 8.1 HIGH

EG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication Attempts_CVE-2025-46414

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The affected product does not limit the number of attempts for inputting
the correct PIN for a registered product, which may allow an attacker
to gain unauthorized access using brute-force methods if they possess a
valid device serial number. The API provides clear feedback when the
correct PIN is entered. This vulnerability was patched in a server-side
update on April 6, 2025.

Basic Information

ID CVE-2025-46414
Source icscert
Published Aug 8, 2025 at 16:17

Affected Product

Vendor EG4 Electronics
Product EG4 12kPV
Version all versions
Affected Versions EG4 Electronics EG4 12kPV all versions
EG4 Electronics EG4 18kPV all versions
EG4 Electronics EG4 Flex 21 all versions
EG4 Electronics EG4 Flex 18 all versions
EG4 Electronics EG4 6000XP all versions
EG4 Electronics EG4 12000XP all versions
EG4 Electronics EG4 GridBoss all versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.