Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9w95-xvpv-cvjw

Опубликовано: 28 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.

EPSS

Процентиль: 8%
0.00185
Низкий

8.6 High

CVSS4

Дефекты

CWE-1188

Связанные уязвимости

nvd
2 месяца назад

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.

EPSS

Процентиль: 8%
0.00185
Низкий

8.6 High

CVSS4

Дефекты

CWE-1188