CVE-2023-25912: Danfoss Ak-EM100 Firmware

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values.

Affected products

  • Danfoss Ak-EM100 Firmware: before 2.2.0.12 (fixed in 2.2.0.12)

Published 2023-06-11. Last modified 2026-06-17.