Xzeres manufactures wind turbine control and monitoring systems, particularly its 442SR model and associated operating software, which sit at the intersection of renewable-energy infrastructure and remote management interfaces. The durable signal from its vulnerability disclosures centers on web-facing input handling, with recurrent exposure to cross-site request forgery and cross-site scripting weaknesses typical of supervisory control systems that lack mature input sanitization. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xzeres over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2287MEDIUM Cross-site scripting (XSS) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Mar 19, 2016 | 6.1 | 22 | NO | NO |
CVE-2015-3950MEDIUM Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that select a | Jun 5, 2015 | 6.8 | 18 | NO | NO |
CVE-2015-0985MEDIUM Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that modify th | Mar 31, 2015 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xzeres.
Media articles that mention a CVE ID that affects a product developed by Xzeres — matched by CVE ID, not by vendor name.