Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-43659

Опубликовано: 09 янв. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

After gaining access to the firmware of a charging station, a file at can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers.

This issue affects Iocharger firmware for AC models before firmware version 25010801.

The issue is addressed by requiring a mandatory password change on first login, it is still recommended to change the password on older models.

Likelihood: Moderate – The attacker will first have to abuse a code execution or file inclusion vulnerability (for example by using .sh) to gain access to the .json file, or obtain a firmware dump of the charging station or obtain the firmware via other channels.

Impact: Critical – All chargers using Iocharger firmware for AC models started with the same initial password. For models with firmware version before 25010801 a password change was not mandatory. It is therefore very likely that this firmware password is still active on many chargers. Th

EPSS

Процентиль: 28%
0.00101
Низкий

7.2 High

CVSS3

Дефекты

CWE-256

Связанные уязвимости

CVSS3: 7.2
github
около 1 года назад

After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. The issue is addressed by requiring a mandatory password change on first login, it is still recommended to change the password on older models. Likelihood: Moderate – The attacker will first have to abuse a code execution or file inclusion vulnerability (for example by using <redacted>.sh) to gain access to the <redacted>.json file, or obtain a firmware dump of the charging station or obtain the firmware via other channels. Impact: Critical – All chargers using Iocharger firmware for AC models started with the same initial password. For models with firmware version before 25010801 a password change was not mandatory. It is therefore very likely that this firmware password is still active on many chargers....

EPSS

Процентиль: 28%
0.00101
Низкий

7.2 High

CVSS3

Дефекты

CWE-256