Total
                    7 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2023-25911 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2025-01-17 | N/A | 9.9 CRITICAL | 
| The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters. | |||||
| CVE-2023-25912 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2024-11-21 | N/A | 5.3 MEDIUM | 
| The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values. | |||||
| CVE-2023-22586 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2024-11-21 | N/A | 7.7 HIGH | 
| The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter. | |||||
| CVE-2023-22585 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2024-11-21 | N/A | 9.0 CRITICAL | 
| The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. | |||||
| CVE-2023-22584 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2024-11-21 | N/A | 7.5 HIGH | 
| The Danfoss AK-EM100 stores login credentials in cleartext. | |||||
| CVE-2023-22583 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2024-11-21 | N/A | 10.0 CRITICAL | 
| The Danfoss AK-EM100 web forms allow for SQL injection in the login forms. | |||||
| CVE-2023-22582 | 1 Danfoss | 2 Ak-em100, Ak-em100 Firmware | 2024-11-21 | N/A | 9.0 CRITICAL | 
| The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. | |||||
