8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The affected product does not limit the number of attempts for inputting
the correct PIN for a registered product, which may allow an attacker
to gain unauthorized access using brute-force methods if they possess a
valid device serial number. The API provides clear feedback when the
correct PIN is entered. This vulnerability was patched in a server-side
update on April 6, 2025.
the correct PIN for a registered product, which may allow an attacker
to gain unauthorized access using brute-force methods if they possess a
valid device serial number. The API provides clear feedback when the
correct PIN is entered. This vulnerability was patched in a server-side
update on April 6, 2025.
Basic Information
ID
CVE-2025-46414
Source
icscert
Published
Aug 8, 2025 at 16:17
Affected Product
Vendor
EG4 Electronics
Product
EG4 12kPV
Version
all versions
Affected Versions
EG4 Electronics EG4 12kPV all versions
EG4 Electronics EG4 18kPV all versions
EG4 Electronics EG4 Flex 21 all versions
EG4 Electronics EG4 Flex 18 all versions
EG4 Electronics EG4 6000XP all versions
EG4 Electronics EG4 12000XP all versions
EG4 Electronics EG4 GridBoss all versions
EG4 Electronics EG4 18kPV all versions
EG4 Electronics EG4 Flex 21 all versions
EG4 Electronics EG4 Flex 18 all versions
EG4 Electronics EG4 6000XP all versions
EG4 Electronics EG4 12000XP all versions
EG4 Electronics EG4 GridBoss all versions