Binom3 manufactures universal multifunctional electric power quality meters, and its vulnerability footprint centers on web-interface and authentication weaknesses in the meter and its firmware, including CSRF, cross-site scripting, hard-coded credentials, and missing authentication controls. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Binom3 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5162CRITICAL An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configura | Feb 13, 2017 | 9.8 | 40 | NO | YES |
CVE-2017-5166CRITICAL An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. An INFORMATION EXPOSURE flaw can be used to gain privileged access to the device. | Feb 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-5167HIGH An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords. | Feb 13, 2017 | 8.6 | 27 | NO | NO |
CVE-2017-5164MEDIUM An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Input sent from a malicious client is not properly verified by the server. An attacker can | Feb 13, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-5165HIGH An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful expl | Feb 13, 2017 | 7.6 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Binom3.
Media articles that mention a CVE ID that affects a product developed by Binom3 — matched by CVE ID, not by vendor name.