Security Vulnerabilities
- CVEs Published In April 2025
An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 1.8.
Unauthenticated attackers can rename "rooms" of arbitrary users.
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
An attacker can export other users' plant information.
An unauthenticated attacker can hijack other users' devices and potentially control them.
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44.
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.