CVE-2023-36607: Ovarro Tbox LT2 Firmware

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.

Affected products

  • Ovarro Tbox LT2 Firmware: up to and including 1.50.598
  • Ovarro Tbox Ms-CPU32-s2 Firmware: up to and including 1.50.598
  • Ovarro Tbox Ms-CPU32 Firmware: up to and including 1.50.598
  • Ovarro Tbox RM2 Firmware: up to and including 1.50.598
  • Ovarro Tbox TG2 Firmware: up to and including 1.50.598

Published 2023-06-29. Last modified 2026-06-17.