The server in Circontrol Raption versions through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection.
2a13323836730c890a63f333a24fcfb62637513c16193386327b7be986133bb0
Novus Management System versions prior to 1.51.2 suffer from cross site scripting and directory traversal vulnerabilities.
a65d049ebbdbe6ea6605dde31e263ad17f342eaa1325232c9713027697ce29ea