Command Injection Vulnerability in Iocharger Firmware for AC Models
CVE-2024-43650
9.3CRITICAL
Key Information:
- Vendor
- Iocharger
- Status
- Iocharger Firmware For Ac Models
- Vendor
- CVE Published:
- 9 January 2025
Summary
A command injection vulnerability exists in the firmware of Iocharger AC models, enabling unauthorized execution of operating system commands with root privileges. This flaw can be exploited remotely, provided the attacker has a low-privilege account or convinces an authorized user to send a specially crafted HTTP request. Affected versions include all firmware prior to version 24120701. Exploiting this vulnerability gives attackers full control over the charging station, allowing them to modify, add, or delete critical files and services. Given that this is an electric vehicle charger, successful exploitation may also pose safety risks.
Affected Version(s)
Iocharger firmware for AC models 0 < 24120701
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Wilco van Beijnum
Harm van den Brink (DIVD)
Frank Breedijk (DIVD)