Command Injection Vulnerability in Iocharger Firmware for AC Models
CVE-2024-43654
What is CVE-2024-43654?
The Iocharger AC EV charger firmware contains a command injection vulnerability that allows attackers with low privilege accounts to execute arbitrary commands as root. This vulnerability affects all AC models running firmware versions prior to 25010801. Attackers may exploit this weakness by crafting specific HTTP requests that leverage improper neutralization of special elements. Once exploited, they gain full control over the charging station, enabling them to add, modify, or delete files and services at will. This poses not only security risks but also potential safety hazards due to the nature of the device handling significant power.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Iocharger firmware for AC models 0 < 25010801
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
