Vulnerability record · CVE-2022-29298 · published 12 May 2022
CVE-2022-29298: SolarView Compact directory traversal exposes sensitive files
Contec · Sv Cpt Mc310 Firmware
SolarView Compact version 6.00 is vulnerable to directory traversal (CWE-22), letting an attacker read files outside the intended web root. Because the affected device is a solar power monitoring product, exposed files may include configuration and credential material. The flaw is remotely reachable and requires no authentication or user interaction.
Description
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with no authentication required, public exploit code available and very high EPSS, though no KEV listing or confirmed in-the-wild use is recorded.
What it is
SolarView Compact version 6.00 is vulnerable to directory traversal (CWE-22), letting an attacker read files outside the intended web root. Because the affected device is a solar power monitoring product, exposed files may include configuration and credential material. The flaw is remotely reachable and requires no authentication or user interaction.
Impact
An attacker gains read access to sensitive files on the device, which can reveal credentials, configuration or other data useful for further compromise. There is no evidence in the record of code execution or data modification.
Attack surface
Reachable over the network via the web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is needed. The description does not name the specific endpoint or parameter.
Exploitation
Public exploit code is referenced (PacketStorm and a Google Drive link tagged Exploit), and EPSS is 0.468 (98.8th percentile), indicating elevated likelihood. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Apply the vendor patch or fixed firmware for SolarView Compact 6.00; if none is available, isolate the device.
- Restrict network access to the device web interface to trusted management networks or VPN only.
- Place the device behind a reverse proxy or WAF that normalizes and blocks path traversal sequences.
- Rotate any credentials or secrets that may have been stored in files reachable through the traversal.
- Monitor vendor advisories for updated firmware, since the record does not list a fixed version.
Detection
- Inspect web server or proxy logs for requests containing ../, ..%2f, or encoded traversal sequences targeting the SolarView interface.
- Alert on HTTP responses returning files outside expected web content paths or unusual file types.
- Baseline normal request patterns to the device and flag anomalous file-path parameters.
- Review device logs for repeated 200 responses to traversal-style requests from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/167383/SolarView-Compact-6.00-Directory-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://drive.google.com/file/d/1-RHw9ekVidP8zc0xpbzBXnse2gSY1xbH/view?usp=sharing | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/167383/SolarView-Compact-6.00-Directory-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://drive.google.com/file/d/1-RHw9ekVidP8zc0xpbzBXnse2gSY1xbH/view?usp=sharing | ExploitThird Party Advisory |
Track CVE-2022-29298 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29298), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.