Summary
Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
…Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device.
The following versions of Johnson Controls EasyIO FG are affected:
- EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873)
| CVSS | Vendor | …
|---|
Summary
Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution.
The following versions of Savannah lwIP SMTP client are affected:
- lwIP SMTP client 2.2.1 (CVE-2026-15340)
| CVSS | …
|---|
Summary
Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. Please refer to the Recommended …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.
The following versions of Armatura LLC Armatura One …
Summary
Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
- …
Summary
Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
The following versions of Monta monta.app are affected:
- monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
Summary
Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
- EasyIO …