CVE-2021-34588
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-425
- Published
- 2022-04-27
- Last modified
- 2026-03-13
Affected products
- Bender / ebee CC612
- Bender / ebee CC612
- Bender / ebee CC612
- Bender / ebee CC612
- Bender / ebee CC613
- Bender / ebee CC613
- Bender / ebee CC613
- Bender / ebee CC613
Weakness type
Related vulnerabilities
- CVE-2024-45195 — Apache OFBiz: Confused controller-view authorization logic (forced browsing)
- CVE-2025-26689 — Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker
- CVE-2024-24592 — Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta
- CVE-2024-0204 — Authentication Bypass in GoAnywhere MFT
- CVE-2025-55736 — flaskBlog allows arbitrary privilege escalation
- CVE-2025-1542 — Improper permission control in OXARI ServiceDesk
- CVE-2024-6188 — Parsec Automation TrackSYS pagedefinition direct request
- CVE-2025-48207 — The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.