Skip to the content.

CVE-2023-25911

OS Command Injection in Danfoss AK-EM 100

CVE CVE-2023-25911
Title OS Command Injection in Danfoss AK-EM 100
Credits
Affected products
Product Affected Unaffected Unknown
Danfoss AK-EM 100 = < 2.2.0.12 ()
everything else
CVSS Base score: 9.9 (CRITICAL)
References
Problem type(s) CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Date published
Last modified

Description

The Danfoss AK-EM 100 web applications allow for OS command injection through the web application parameters.

Workaround(s)

The AK-EM 100 has been declared End of Life (EOL). Danfoss advises phasing out this type of device.


JSON version.