CVE-2019-19229
Published Dec 4, 2019admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
Vendor/product archive
2 CVEs tagged to fronius / galvo_1.5-1_firmware — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf f…