Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-23788
Disclosure Date: February 14, 2024 (last updated December 18, 2024)
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
0
Attacker Value
Unknown
CVE-2024-23787
Disclosure Date: February 14, 2024 (last updated January 04, 2025)
Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.
0
Attacker Value
Unknown
CVE-2024-23786
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
0
Attacker Value
Unknown
CVE-2024-23785
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.
0
Attacker Value
Unknown
CVE-2024-23784
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page of the affected product.
0
Attacker Value
Unknown
CVE-2024-23783
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.
0