The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpserver1, and pingip.
This Cyber News was published on www.tenable.com. Publication date: Fri, 08 Nov 2024 17:01:03 +0000