CVE-2023-46665: Sielco POLYECO1000 Firmware
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.
Affected products
- Sielco POLYECO1000 Firmware: version 1.9.3 only; version 1.9.4 only; version 2.0.6 only; version 10.19 only
- Sielco POLYECO300 Firmware: version 2.0.0 only; version 2.0.2 only; version 10.19 only
- Sielco POLYECO500 Firmware: version 1.7.0 only; version 10.16 only
Published 2023-10-26. Last modified 2026-06-17.