PatchSiren

Locusenergy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Locusenergy CVE published 2017-02-13

CVE-2016-5782

CVE-2016-5782 describes an input-validation flaw in the PHP script used by Locus Energy LGate meters to manage meter parameters, voltage monitoring, and network configuration. The CVE record rates the issue HIGH with CVSS 8.6 and a network attack vector with no privileges or user interaction required. The NVD entry maps the problem to CWE-20 (Improper Input Validation) and lists affected LGate firmware pl [truncated]