PT-2026-1135 · Nuvation Energy · Multi-Stack Controller

CVE-2025-64120

·

Publicado

2025-01-13

·

Atualizado

2026-01-03

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:I
Name of the Vulnerable Software and Affected Versions Nuvation Energy Multi-Stack Controller versions 2.3.8 through 2.5.0
Description A flaw exists in Nuvation Energy Multi-Stack Controller that allows for OS Command Injection. This issue could allow an attacker to execute arbitrary commands on the system. The vulnerability grants shell access with minimal authentication, which is particularly critical for energy storage systems.
Recommendations Update to a version later than 2.5.0.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00781
CVE-2025-64120

Produtos afetados

Multi-Stack Controller