CVE-2012-5861

Sinapsi eSolar, eSolar DUO, and eSolar Light < 2.0.2870_xxx_2.2.12 - Unauthenticated SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5861. PoCs published by Roberto Paleari.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in the Schneider Electric Ezylog photovoltaic SCADA management server, including SQL injection, hard-coded accounts, command injection, and broken session enforcement. It provides technical analysis, code snippets, and exploitation examples.

Description

These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.

Exploits (1)

exploitdb WRITEUP
by Roberto Paleari · textwebappsphp
https://www.exploit-db.com/exploits/21273

This advisory details multiple vulnerabilities in the Schneider Electric Ezylog photovoltaic SCADA management server, including SQL injection, hard-coded accounts, command injection, and broken session enforcement. It provides technical analysis, code snippets, and exploitation examples.

Classification
Writeup 100%
Attack Type
Sqli | Rce | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Schneider Electric Ezylog photovoltaic SCADA management server (all firmware versions analyzed)
No auth needed
Prerequisites: Network access to the management interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/21273/
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80200

Scores

EPSS 0.0408
EPSS Percentile 89.4%

Details

CWE
CWE-89
Status published
Products (7)
Sinapsi/eSolar < 2.0.2870_xxx_2.2.12
Sinapsi/eSolar DUO < 2.0.2870_xxx_2.2.12
Sinapsi/eSolar Light < 2.0.2870_xxx_2.2.12
sinapsitech/esolar_duo_photovoltaic_system_monitor
sinapsitech/esolar_light_photovoltaic_system_monitor
sinapsitech/esolar_photovoltaic_system_monitor
sinapsitech/sinapsi_firmware < 2.0.2870
Published Nov 23, 2012
Tracked Since Feb 18, 2026