Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.dragos.com/community/advisories/CVE-2025-64119 |
|
Thu, 26 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuvationenergy
Nuvationenergy nplatform Nuvationenergy nuvmsc3-04s-c Nuvationenergy nuvmsc3-08s-c Nuvationenergy nuvmsc3-12s-c Nuvationenergy nuvmsc3-16s-c |
|
| CPEs | cpe:2.3:a:nuvationenergy:nplatform:*:*:*:*:*:*:*:* cpe:2.3:h:nuvationenergy:nuvmsc3-04s-c:-:*:*:*:*:*:*:* cpe:2.3:h:nuvationenergy:nuvmsc3-08s-c:-:*:*:*:*:*:*:* cpe:2.3:h:nuvationenergy:nuvmsc3-12s-c:-:*:*:*:*:*:*:* cpe:2.3:h:nuvationenergy:nuvmsc3-16s-c:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nuvationenergy
Nuvationenergy nplatform Nuvationenergy nuvmsc3-04s-c Nuvationenergy nuvmsc3-08s-c Nuvationenergy nuvmsc3-12s-c Nuvationenergy nuvmsc3-16s-c |
|
| Metrics |
cvssV3_1
|
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuvation Energy
Nuvation Energy multi-stack Controller |
|
| Vendors & Products |
Nuvation Energy
Nuvation Energy multi-stack Controller |
Sat, 03 Jan 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue. | Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary Bridging.This issue affects Multi-Stack Controller (MSC): through and including release 2.5.1. |
| Title | Nuvation Energy nCloud Client-to-Client Communication | Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 02 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): through 2.5.1. | A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue. |
| Title | Nuvation Energy Multi-Stack Controller OS Command Injection | Nuvation Energy nCloud Client-to-Client Communication |
| Weaknesses | CWE-78 | CWE-441 |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 02 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): through 2.5.1. | |
| Title | Nuvation Energy Multi-Stack Controller OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Dragos
Published:
Updated: 2026-01-05T20:37:19.148Z
Reserved: 2025-10-27T17:12:37.786Z
Link: CVE-2025-64123
Updated: 2026-01-05T20:32:31.179Z
Status : Analyzed
Published: 2026-01-02T22:15:44.787
Modified: 2026-02-26T19:59:40.363
Link: CVE-2025-64123
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:13:50Z