CVE-2022-4557: Gruparge Smartpower

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

Affected products

  • Gruparge Smartpower: before 23.01.01 (fixed in 23.01.01)

Published 2023-02-12. Last modified 2026-06-17.