Echarge's vulnerability profile centers on its Salia PLCC payment and loyalty card controller and associated firmware, a specialized point-of-sale component with a narrow installed base. The durable signal reflects command-injection and data-authenticity weaknesses that arise in payment terminal firmware, underscoring the importance of validating input and verifying transactions in environments handling sensitive financial data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Echarge over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11666CRITICAL Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verif | Nov 24, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-11665HIGH Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affect | Nov 24, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Echarge.
Media articles that mention a CVE ID that affects a product developed by Echarge — matched by CVE ID, not by vendor name.