Vulnerabilities (CVE)

Filtered by vendor Franklinfueling Subscribe
Filtered by product Colibri Firmware
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5885 1 Franklinfueling 2 Colibri, Colibri Firmware 2024-05-17 N/A 6.5 MEDIUM
The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.
CVE-2022-44039 1 Franklinfueling 1 Colibri Firmware 2023-12-10 N/A 9.8 CRITICAL
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ΒΆΒΆ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.
CVE-2021-46417 1 Franklinfueling 2 Colibri, Colibri Firmware 2023-12-10 7.8 HIGH 7.5 HIGH
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.