← back
CVE-2025-47872

EG4 Electronics EG4 Inverters Observable Discrepancy

CVSS 6.9 MEDIUMEPSS 0.3%CWE-203
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →