Server-side request forgery vulnerability in Energy...
Critical severity
Unreviewed
Published
Aug 9, 2024
to the GitHub Advisory Database
•
Updated Dec 13, 2024
Description
Published by the National Vulnerability Database
Feb 14, 2024
Published to the GitHub Advisory Database
Aug 9, 2024
Last updated
Dec 13, 2024
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
References