Description
The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.
Scores
CVSS v3
8.8
EPSS
0.0003
EPSS Percentile
7.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-494
Status
published
Products (7)
EG4 Electronics/EG4 12000XP
all versions
EG4 Electronics/EG4 12kPV
all versions
EG4 Electronics/EG4 18kPV
all versions
EG4 Electronics/EG4 6000XP
all versions
EG4 Electronics/EG4 Flex 18
all versions
EG4 Electronics/EG4 Flex 21
all versions
EG4 Electronics/EG4 GridBoss
all versions
Published
Aug 08, 2025
Tracked Since
Feb 18, 2026