EG4 Electronics EG4 Inverters Observable Discrepancy
Vulnerability Description
The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-47872
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Anthony Rose of BC Security reported these vulnerabilities to CISA.
References
More from EG4 Electronics
View All →Affected Vendor
EG4 Electronics
View all reports →