Cross-Site Request Forgery Vulnerability in Schneider Electric Charging Stations
CVE-2021-22725
8.8HIGH
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 28 January 2022
What is CVE-2021-22725?
A Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to execute unauthorized actions on behalf of a user by exploiting crafted malicious parameters submitted in POST requests to the Schneider Electric charging station web server. This flaw affects multiple models, including EVlink City, EVlink Parking, and Smart Wallbox devices, which may put user accounts at risk if proper authentication measures are not implemented. To mitigate this issue, it is crucial for users to upgrade their systems to the recommended version R8 V3.4.0.2 or later.