Janitza UMG 96RM-E 24V和Janitza UMG 96RM-E 230V都是德国Janitza公司的一个多功能电能质量分析仪。 Janitza UMG 96RM-E 24V和Janitza UMG 96RM-E 230V存在操作系统命令注入漏洞,该漏洞源于功率分析仪在处理通过Modbus-TCP和Modbus-RTU协议传输的指令时,存在命令注入缺陷。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Janitza | UMG 96RM-E 24V(5222063) | 0.0 ~ 3.13 | - |
|
| Janitza | UMG 96RM-E 230V(5222062) | 0.0 ~ 3.13 | - |
|
| Weidmueller | ENERGY METER 750-230 (2540910000) | 0.0 ~ 3.13 | - |
|
| Weidmueller | ENERGY METER 750-24 (2540900000) | 0.0 ~ 3.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-41710 | 6.5 MEDIUM | Use of Hard-coded Credentials in power analyzer |
| CVE-2025-41712 | 6.5 MEDIUM | Incorrect Permission Assignment on power analyzer |
| CVE-2025-41711 | 5.3 MEDIUM | Use of a Broken or Risky Cryptographic Algorithm for firmware images of power analyzer |
No comments yet