This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis →
Q1What is this vulnerability? (Essence + Consequences)
🚨 **Essence**: Enel X Waybox 3.0 has a critical flaw in its Web Admin App. Attackers can send arbitrary SQL requests via `/admin/versions.php`. 📉 **Consequences**: Full compromise of the internal database.…
🛡️ **Root Cause**: **SQL Injection (SQLi)**. Specifically mapped to **CWE-89**. The application fails to sanitize inputs in the `versions.php` endpoint, allowing direct manipulation of the backend database.
Q3Who is affected? (Versions/Components)
🏠 **Affected Product**: Enel X **Waybox 3.0** (Home Charging Station). 📦 **Component**: The internal Web Management Application. ⚠️ **Vendor**: Enel X.…
💀 **Attacker Capabilities**: Since it's SQLi, hackers can: 🔓 **Read** all internal data. 🗑️ **Delete/Modify** records. 💥 **Execute** administrative commands on the DB.…
📜 **Public Exploit**: The provided data shows `pocs: []`, meaning **no specific PoC code** is listed in this dataset. 🌍 **However**, SQLi is a well-known technique.…
🔍 **Self-Check**: Scan your network for Enel X Waybox devices. 🕵️♂️ **Test**: Attempt to access `/admin/versions.php`. 🧪 **Verify**: If the endpoint is reachable without auth, it is vulnerable.…
🩹 **Official Fix**: Yes. Enel X released a **Security Bulletin (06-2024-V1)**. 📄 **Reference**: Check the official Enel X support documentation for firmware updates or patches addressing the `versions.php` endpoint.
Q9What if no patch? (Workaround)
🚧 **No Patch Workaround**: 1. **Isolate**: Block access to the device's admin interface via Firewall. 2. **Disable**: Turn off the Web Admin feature if possible. 3.…
🔥 **Urgency**: **CRITICAL**. 🚨 **Priority**: **P1**. With a CVSS of 10.0 and no authentication required, this is an immediate threat. Patch or isolate these devices **NOW**.