CVE-2012-5861

These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sinapsitech:sinapsi_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:sinapsitech:esolar_duo_photovoltaic_system_monitor:-:*:*:*:*:*:*:*
cpe:2.3:h:sinapsitech:esolar_light_photovoltaic_system_monitor:-:*:*:*:*:*:*:*
cpe:2.3:h:sinapsitech:esolar_photovoltaic_system_monitor:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-11-23 12:09

Updated : 2025-07-08 16:15


NVD link : CVE-2012-5861

Mitre link : CVE-2012-5861

CVE.ORG link : CVE-2012-5861


JSON object : View

Products Affected

sinapsitech

  • esolar_duo_photovoltaic_system_monitor
  • esolar_photovoltaic_system_monitor
  • sinapsi_firmware
  • esolar_light_photovoltaic_system_monitor
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')