References https://github.com/YZS17/CVE/blob/main/Salia_PLCC/Salia_PLCC_Slave_v2.2.0_File_Upload.md https://mrxn.net/jswz/salia-firmware-upload-rce.html https://cn-sec.com/archives/5065570.html https://nvd.nist.gov/vuln/detail/CVE-2025-5873 https://www.cve.org/CVERecord?id=CVE-2025-5873 https://vuldb.com/?id.311632 https://github.com/Mr-xn/Penetration_Testing_POC https://www.isssource.com/no-fix-for-hardy-barth-salia-ev-charge-controller/
Related VulnerabilitiesPoCCVE-2016-1555: NETGEAR WNAP320 Access Point Firmware - Remote Command InjectionPoCCVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code ExecutionPoCCVE-2022-29383: NETGEAR ProSafe SSL VPN firmware - SQL InjectionPoCCVE-2022-32429: MSNSwitch Firmware MNT.2408 - Authentication BypassPoCCVE-2022-33174: Powertek Firmware <3.30.30 - Authorization BypassPoCCVE-2022-45699: APsystems ECU-R Firmware - Command InjectionPoCCVE-2023-31446: Cassia Gateway Firmware - Remote Code ExecutionPoCCVE-2024-29972: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor AccountPoCCVE-2024-29973: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command InjectionSalia PLCC /firmware.php 文件上传漏洞Salia PLCC /check.php 未授权访问漏洞