Bkw's vulnerability profile centers on the Solar-Log 500 solar-energy monitoring device and its associated firmware, with observed issues reflecting the embedded and remote-management context of the product. The durable signal is a combination of cleartext storage of sensitive information and missing authentication controls for critical functions, both characteristic of legacy embedded systems where operational simplicity was prioritized over defense-in-depth. Current exploitation activity, severity levels, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bkw over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34543HIGH The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting | Dec 7, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-34544MEDIUM An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive infor | Dec 7, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bkw.
Media articles that mention a CVE ID that affects a product developed by Bkw — matched by CVE ID, not by vendor name.