Solarcontrols maintains a focused portfolio of heating and HVAC control products, including the Heating Control Downloader and WattConfig M, that operate in embedded thermal-management environments. The durable signal from its disclosures centers on path-handling weaknesses—specifically uncontrolled search path elements—which are characteristic of locally executed installers and configuration utilities in this product class. Specific exploitation activity, public exploit availability, and current severity assessment are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Solarcontrols over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9646HIGH An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An uncontrolled search path element | Aug 14, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-9648HIGH An Uncontrolled Search Path Element issue was discovered in Solar Controls WATTConfig M Software Version 2.5.10.1 and prior. An uncontrolled search path element has been identified | Aug 14, 2017 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Solarcontrols.
Media articles that mention a CVE ID that affects a product developed by Solarcontrols — matched by CVE ID, not by vendor name.