Badgermeter develops a narrow product line centered on its Monitool monitoring and management applications, which despite modest disclosure volume occupy a notable presence in specialized operational contexts. The recurring vulnerability profile reflects classic web-application attack surfaces: path traversal, SQL injection, cross-site scripting, and information exposure weaknesses that cluster around input validation and data-handling practices in browser-facing interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Badgermeter over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1301HIGH SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_userna | Mar 12, 2024 | 7.5 | 25 | NO | NO |
CVE-2020-12507HIGH In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of | Nov 15, 2022 | 8.8 | 22 | NO | NO |
CVE-2024-1303MEDIUM Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an authentic | Mar 12, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-1302MEDIUM Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file | Mar 12, 2024 | 5.5 | 19 | NO | NO |
CVE-2020-12508HIGH In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the image-relocator module. | Nov 15, 2022 | 7.5 | 19 | NO | NO |
CVE-2020-12509HIGH In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the camera-file module. | Nov 7, 2022 | 7.5 | 19 | NO | NO |
CVE-2024-1304MEDIUM Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted j | Mar 12, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Badgermeter.
Media articles that mention a CVE ID that affects a product developed by Badgermeter — matched by CVE ID, not by vendor name.