CVE-2024-1889: SMA Clcon-10 Firmware

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.

Affected products

  • SMA Clcon-10 Firmware: version 01.05.01.r only
  • SMA Clcon-S-10 Firmware: version 01.05.01.r only

Published 2024-02-26. Last modified 2026-06-17.