CVE-2012-6428: Carlosgavazzi Eos-Box Photovoltaic Monitoring System

High severity, CVSS 10.0. EPSS: 1.5% chance of exploitation in the next 30 days.

The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

Affected products

  • Carlosgavazzi Eos-Box Photovoltaic Monitoring System
  • Carlosgavazzi Eos-Box Photovoltaic Monitoring System Firmware: up to and including 1.0.0

Published 2012-12-23. Last modified 2026-06-16.