Description
The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.
Scores
CVSS v3
5.8
EPSS
0.0006
EPSS Percentile
18.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-203
Status
published
Products (7)
EG4 Electronics/EG4 12000XP
all versions
EG4 Electronics/EG4 12kPV
all versions
EG4 Electronics/EG4 18kPV
all versions
EG4 Electronics/EG4 6000XP
all versions
EG4 Electronics/EG4 Flex 18
all versions
EG4 Electronics/EG4 Flex 21
all versions
EG4 Electronics/EG4 GridBoss
all versions
Published
Aug 08, 2025
Tracked Since
Feb 18, 2026