CVE-2024-8893

Published Feb 14, 2025

Last updated 14 days ago

Overview

Description
Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully access the web interface of the inverter via Wi‑Fi.This issue affects GW1500‑XS: 1.1.2.1.
Source
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.3
Impact score
3.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity
HIGH

Weaknesses

a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
CWE-798

Social media

Hype score
Not currently trending