Enelx's vulnerability footprint centers on a specialized energy-management appliance platform, the Waybox Pro, which serves as a control and monitoring point in commercial power-management infrastructure. The recurring exposure pattern reflects application-layer input handling, access control, and information disclosure weaknesses that are characteristic of web-facing administrative interfaces in industrial and building-management devices. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enelx over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29120HIGH Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system. | Nov 5, 2024 | 8.8 | 28 | NO | NO |
CVE-2023-29126HIGH The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication. | Nov 5, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-29121HIGH Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system. | Nov 5, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-29119HIGH Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php. | Nov 5, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-29118HIGH Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php. | Nov 5, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-29117HIGH Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system. | Nov 5, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-29125HIGH A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700. | Nov 5, 2024 | 8.0 | 24 | NO | NO |
CVE-2023-29115MEDIUM In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot). | Nov 5, 2024 | 6.5 | 21 | NO | NO |
CVE-2023-29116MEDIUM Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be o | Nov 5, 2024 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enelx.
Media articles that mention a CVE ID that affects a product developed by Enelx — matched by CVE ID, not by vendor name.