Hard-coded Credentials Vulnerability in Schneider Electric's EVlink Products
CVE-2021-22730
Key Information:
What is CVE-2021-22730?
A vulnerability exists in Schneider Electric's EVlink City, EVlink Parking, and EVlink Smart Wallbox products due to hard-coded credentials, allowing attackers to exploit the web server of the charging stations. This exploitation could grant unauthorized administrative access, posing significant security risks to users and systems relying on these devices.
Affected Version(s)
EVlink City (EVC1S22P4 / EVC1S7P4 all prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all prior to R8 V3.4.0.1 ) EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 )