Vulnerabilities > ABB > Txpert HUB Coretec 4 Firmware > 2.1.1

DATE CVE VULNERABILITY TITLE RISK
2023-06-28 CVE-2023-2625 OS Command Injection vulnerability in ABB Txpert HUB Coretec 4 Firmware
A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN.
low complexity
abb CWE-78
8.0
2022-06-07 CVE-2021-35532 Unrestricted Upload of File with Dangerous Type vulnerability in ABB Txpert HUB Coretec 4 Firmware
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product.
local
low complexity
abb CWE-434
7.2