Vulnerabilities > Contec

DATE CVE VULNERABILITY TITLE RISK
2022-08-16 CVE-2022-35239 Improper Input Validation vulnerability in Contec Sv-Cpt-Mc310 Firmware and Sv-Cpt-Mc310F Firmware
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files.
network
low complexity
contec CWE-20
8.8
2022-06-21 CVE-2022-31373 Cross-site Scripting vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
network
low complexity
contec CWE-79
6.1
2022-06-21 CVE-2022-31374 Unrestricted Upload of File with Dangerous Type vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
network
low complexity
contec CWE-434
critical
9.8
2022-05-12 CVE-2022-29298 Path Traversal vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.00
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
network
low complexity
contec CWE-22
7.5
2022-05-12 CVE-2022-29302 Files or Directories Accessible to External Parties vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.00
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
local
low complexity
contec CWE-552
5.5
2022-05-12 CVE-2022-29303 OS Command Injection vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.00
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
network
low complexity
contec CWE-78
critical
9.8
2021-02-24 CVE-2021-20662 Missing Authentication for Critical Function vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information without the access privileges via unspecified vectors.
network
low complexity
contec CWE-306
7.5
2021-02-24 CVE-2021-20661 Path Traversal vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
network
low complexity
contec CWE-22
8.1
2021-02-24 CVE-2021-20660 Cross-site Scripting vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
network
low complexity
contec CWE-79
6.1
2021-02-24 CVE-2021-20659 Unrestricted Upload of File with Dangerous Type vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.
network
low complexity
contec CWE-434
8.8