CVE-2021-3252

HIGH

KACO New Energy XP100U - Info Disclosure

Title source: llm

Description

KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.

Scores

CVSS v3 7.5
EPSS 0.0059
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

kaco-newenergy/xp100u_firmware

Timeline

Published Feb 23, 2021
Tracked Since Feb 18, 2026