Summary
Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access.
The following versions …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts.
The following versions of Digi International PortServer TS, Digi One SP IA are affected:
- PortServer TS
- Digi …
Summary
Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack.
The following versions of Hydro-Québec Le Circuit Electrique charging station backend are affected:
- Le Circuit Electrique charging station backend
| CVSS | …
|---|
Summary
Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens …
Summary
Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.
The following versions of ST Engineering iDirect iQ-Series Terminals are affected:
- Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057)
- 3315‑Series terminals <=4.5.2.1 …
Summary
Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device.
The following versions of CubeSpace CW0057 Reaction Wheel are affected:
- CW0057 Reaction Wheel
| CVSS | Vendor | Equipment | … |
|---|
Summary
Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices.
The following versions of Gardyn IoT Hub are affected:
- Home Firmware
- Studio Firmware
- Cloud API <2.12.2026 (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477)