NA - CVE-2025-25220 - Improper neutralization of special elements...
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability is exploited, an...
High - CVE-2024-23942 - A local user may find a configuration file on...
A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the...
Critical - CVE-2024-23943 - An unauthenticated remote attacker can gain...
An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. Availability is not affected.
Medium - CVE-2024-41975 - An unauthenticated remote attacker can gain...
An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.
High - CVE-2025-1468 - An unauthenticated remote attacker can gain...
An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.
NA - CVE-2025-2489 - Insecure information storage vulnerability in...
Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in...
NA - CVE-2025-2493 - Path Traversal vulnerability in Softdial...
Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ endpoint to...
NA - CVE-2025-2494 - Unrestricted file upload to Softdial Contact...
Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which...
NA - CVE-2025-2495 - Stored Cross-Site Scripting (XSS) in Softdial...
Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript code injected via the...