Executive brief
A security vulnerability has been identified in the Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform, which is used to manage and monitor industrial power substations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view sensitive operational data or disrupt power management services. This issue is particularly serious because the exploit is publicly available and the vendor has not yet provided a fix.
Technical details
A SQL injection vulnerability exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. The flaw is located within the '/SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree' endpoint and is triggered by manipulating the 'sort' argument. A remote, unauthenticated attacker can exploit this to execute arbitrary SQL commands against the backend database. This can lead to unauthorized data retrieval, modification, or deletion. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available. Public exploit code is reportedly available.
Affected products
- Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2
Timeline
- 2026-05-26: advisory: Initial disclosure by VulDB and NVD
- 2026-05-26: disclosed: Exploit code made public