CVE-2021-3252
7.5 HIGHKACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control
Published: 2021-02-23 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-522
Affected products
| Vendor | Product |
|---|---|
| kaco-newenergy | xp100u_firmware |
Description
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-3252
- [Exploit reference]https://tiger-team-1337.blogspot.com/2021/01/kaco-xp100u-hmi-credential-leak.html
- [Other]https://twitter.com/Kevin2600/status/1351189347501023238
- [Other]https://us-cert.cisa.gov/ics/alerts/ICS-ALERT-15-224-01
- [Exploit reference]https://tiger-team-1337.blogspot.com/2021/01/kaco-xp100u-hmi-credential-leak.html
- [Other]https://twitter.com/Kevin2600/status/1351189347501023238
- [Other]https://us-cert.cisa.gov/ics/alerts/ICS-ALERT-15-224-01
Related CVEs
Same CWE
- CVE-2026-53840 — OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configur... (7.1 HIGH)
- CVE-2026-6517 — Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in ... (6.3 MEDIUM)
- CVE-2026-49949 — CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive crede... (5.3 MEDIUM)
- CVE-2024-45636 — IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user (4.1 MEDIUM)
- CVE-2026-41715 — In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials (6.1 MEDIUM)