CVE-2019-11369: Carel Pcoweb Card Firmware

High severity, CVSS 8.8. EPSS: 8.1% chance of exploitation in the next 30 days.

An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.

Affected products

  • Carel Pcoweb Card Firmware: before b1.2.1 (fixed in b1.2.1)

Published 2019-06-03. Last modified 2026-06-17.