Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
2024-02-14T10:15:08.830
2025-03-19T14:15:36.007
Modified
CVSSv3.1: 8.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sharp | jh-rvb1_firmware | ≤ b0.1.9.1 | Yes |
Hardware | sharp | jh-rvb1 | - | No |
Operating System | sharp | jh-rv11_firmware | ≤ b0.1.9.1 | Yes |
Hardware | sharp | jh-rv11 | - | No |