CVE-2026-5016 is a Server-Side Request Forgery (SSRF) vulnerability affecting elecV2 elecV2P up to version 3.8.3, specifically within the URL Handler component's eAxios function. Rated 7.3 HIGH (CVSS:3.1), this flaw allows unauthenticated remote attackers to manipulate the 'req' argument, potentially leading to information disclosure, data modification, or service disruption. A public exploit is available, increasing the risk of exploitation, though it is not currently listed in CISA's Known Exploited Vulnerabilities catalog. The vendor has been informed but has not yet responded, and community discussion regarding this vulnerability remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ElecV2 | ElecV2P | 3.8.0, 3.8.1, 3.8.2, 3.8.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.