Filtered by vendor Espec Subscriptions
Filtered by product North America Web Controller Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-27845 1 Espec 1 North America Web Controller 2025-08-16 9.8 Critical
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.
CVE-2025-27847 1 Espec 1 North America Web Controller 2025-08-16 4.3 Medium
In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
CVE-2025-27846 1 Espec 1 North America Web Controller 2025-08-16 4.3 Medium
In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.