CVE-2025-24861

An attacker may inject commands via specially-crafted post requests.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:outbackpower:mojave_inverter_oghi8048a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:outbackpower:mojave_inverter_oghi8048a:-:*:*:*:*:*:*:*

History

04 Mar 2025, 19:24

Type Values Removed Values Added
Summary
  • (es) Un atacante puede inyectar comandos a través de solicitudes de publicación especialmente manipuladas.
References () https://old.outbackpower.com/about-outback/contact/contact-us - () https://old.outbackpower.com/about-outback/contact/contact-us - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-17 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-17 - US Government Resource
First Time Outbackpower mojave Inverter Oghi8048a Firmware
Outbackpower
Outbackpower mojave Inverter Oghi8048a
CPE cpe:2.3:h:outbackpower:mojave_inverter_oghi8048a:-:*:*:*:*:*:*:*
cpe:2.3:o:outbackpower:mojave_inverter_oghi8048a_firmware:-:*:*:*:*:*:*:*

13 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-13 22:15

Updated : 2025-03-04 19:24


NVD link : CVE-2025-24861

Mitre link : CVE-2025-24861

CVE.ORG link : CVE-2025-24861


JSON object : View

Products Affected

outbackpower

  • mojave_inverter_oghi8048a
  • mojave_inverter_oghi8048a_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')