An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.vde.com/en/advisories/VDE-2025-012 |
![]() ![]() |
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 26 Feb 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user. | |
Title | SMA: Sunny Portal Remote Code Execution | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-02-26T10:01:50.336Z
Updated: 2025-02-26T15:27:59.319Z
Reserved: 2025-01-27T10:41:55.092Z
Link: CVE-2025-0731

Updated: 2025-02-26T14:50:12.144Z

Status : Received
Published: 2025-02-26T13:15:41.040
Modified: 2025-02-26T13:15:41.040
Link: CVE-2025-0731

No data.