Description
A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.
Scores
CVSS v3
8.8
EPSS
0.0015
EPSS Percentile
34.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1286
Status
published
Products (6)
Sauter/EY-modulo 5 ecos 5 ecos504/505
0.0 - Firmware v6.0
Sauter/EY-modulo 5 modu 5 modu524
0.0 - Firmware v6.0
Sauter/EY-modulo 5 modu 5 modu525
0.0 - Firmware v6.0
Sauter/modulo 6 devices modu612-LC
0.0.0 - Firmware v3.2.0
Sauter/modulo 6 devices modu660-AS
0.0.0 - Firmware v3.2.0
Sauter/modulo 6 devices modu680-AS
0.0.0 - Firmware v3.2.0
Published
Oct 22, 2025
Tracked Since
Feb 18, 2026