CVE-2025-5873 is an unrestricted file upload vulnerability in the web UI component of eCharge Hardy Barth Salia PLCC devices up to version 2.3.81, specifically affecting the /firmware.php file when manipulating the 'media' argument. This medium-severity vulnerability (CVSS 6.3) can be exploited remotely with low attack complexity and low privileges, potentially leading to limited impact on confidentiality, integrity, and availability. While an exploit is publicly available, there is no evidence of active exploitation, no known exploit frameworks (Metasploit, Nuclei, ExploitDB) support it, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ECharge Hardy Barth | Salia PLCC | 2.3.0, 2.3.1, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.3.15, 2.3.16, 2.3.17, 2.3.18, 2.3.19, 2.3.2, 2.3.20, 2.3.21, 2.3.22, 2.3.23, 2.3.24, 2.3.25, 2.3.26, 2.3.27, 2.3.28, 2.3.29, 2.3.3, 2.3.30, 2.3.31, 2.3.32, 2.3.33, 2.3.34, 2.3.35, 2.3.36, 2.3.37, 2.3.38, 2.3.39, 2.3.4, 2.3.40, 2.3.41, 2.3.42, 2.3.43, 2.3.44, 2.3.45, 2.3.46, 2.3.47, 2.3.48, 2.3.49, 2.3.5, 2.3.50, 2.3.51, 2.3.52, 2.3.53, 2.3.54, 2.3.55, 2.3.56, 2.3.57, 2.3.58, 2.3.59, 2.3.6, 2.3.60, 2.3.61, 2.3.62, 2.3.63, 2.3.64, 2.3.65, 2.3.66, 2.3.67, 2.3.68, 2.3.69, 2.3.7, 2.3.70, 2.3.71, 2.3.72, 2.3.73, 2.3.74, 2.3.75, 2.3.76, 2.3.77, 2.3.78, 2.3.79, 2.3.8, 2.3.80, 2.3.81, 2.3.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.