Elspec Ltd operates a specialized power-quality and electrical-diagnostics platform centered on the G5DFR analyzer and its firmware, which sits at the boundary between electrical infrastructure monitoring and networked systems. The disclosed vulnerabilities cluster around the firmware component and reflect the integration challenges inherent to industrial diagnostic devices that bridge legacy electrical systems and modern connectivity. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elspec Ltd over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22080CRITICAL An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing. | Mar 20, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-22081CRITICAL An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism. | Mar 20, 2024 | 9.8 | 24 | NO | NO |
CVE-2024-22078HIGH An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script | Mar 20, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-59392MEDIUM On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset str | Nov 6, 2025 | 6.8 | 22 | NO | NO |
CVE-2024-22079HIGH An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism. | Mar 20, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-22084HIGH An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files. | Mar 20, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-22082HIGH An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused be an attacke | Mar 20, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-46603HIGH An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML | Jan 7, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-46602HIGH An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Serv | Jan 7, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-46601HIGH Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow. | Jan 7, 2025 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elspec Ltd.
Media articles that mention a CVE ID that affects a product developed by Elspec Ltd — matched by CVE ID, not by vendor name.