Enel X Waybox是Enel X公司的一个家庭充电站。 Enel X Waybox 3.0版本存在安全漏洞,该漏洞源于TCF代理服务可用于获取Waybox系统的管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Enel X | JuiceBox Pro 3.0 22kW Cellular | 0 ~ 2.1.1.0_JB3VU096A | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-29120 | 9.6 CRITICAL | Unauthorized Remote Command Execution in Enel X Juicebox |
| CVE-2023-29119 | 9.6 CRITICAL | Unauthorized SQLite Injection |
| CVE-2023-29118 | 9.6 CRITICAL | Unauthorized SQLite Injection in Enel X Juicebox |
| CVE-2023-29125 | 9.0 CRITICAL | Heap overflow in CM_main.exe binary in Enel X JuiceBox |
| CVE-2023-29117 | 8.8 HIGH | Authentication Bypass in JuiceBox Web Manager interface |
| CVE-2023-29122 | 6.7 MEDIUM | Incorrect file ownership of privileged service's libraries in Enel X JuiceBox |
| CVE-2023-29115 | 6.5 MEDIUM | Denial of Service via Web Management interface in Enel X JuiceBox |
| CVE-2023-29114 | 5.7 MEDIUM | Unauthorized System Log Disclosure in Enel X JuiceBox |
| CVE-2023-29116 | 4.3 MEDIUM | PHP Information Disclosure in Enel X JuiceBox |
| CVE-2023-29126 | 4.2 MEDIUM | Insecure loose comparison in Enel X JuiceBox |
No comments yet