Cross-Site Request Forgery Vulnerability in Schneider Electric Charging Stations
CVE-2021-22725
8.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Status
- Vendor
- CVE Published:
- 28 January 2022
Summary
A Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to execute unauthorized actions on behalf of a user by exploiting crafted malicious parameters submitted in POST requests to the Schneider Electric charging station web server. This flaw affects multiple models, including EVlink City, EVlink Parking, and Smart Wallbox devices, which may put user accounts at risk if proper authentication measures are not implemented. To mitigate this issue, it is crucial for users to upgrade their systems to the recommended version R8 V3.4.0.2 or later.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved