Command Injection Vulnerability in Iocharger AC Models Firmware
CVE-2024-43651
9.3CRITICAL
Key Information:
- Vendor
- Iocharger
- Status
- Iocharger Firmware For Ac Models
- Vendor
- CVE Published:
- 9 January 2025
Summary
A command injection vulnerability exists in the firmware of Iocharger AC models prior to version 241207101, allowing attackers to execute arbitrary OS commands with root privileges. This exploit enables full control over the device, allowing for file manipulation and potential pivoting into more sensitive network segments. Attackers require low-level authenticated user access to exploit this vulnerability, which poses significant risks given the nature of electric vehicle charging technology.
Affected Version(s)
Iocharger firmware for AC models 0 < 24120701
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Wilco van Beijnum
Harm van den Brink (DIVD)
Frank Breedijk (DIVD)