Remote Code Execution Vulnerability in eCharge Hardy Barth cPH2 Charging Stations
CVE-2025-3881
8.8HIGH
What is CVE-2025-3881?
The eCharge Hardy Barth cPH2 charging stations are affected by a command injection vulnerability in the handling of the 'ntp' parameter within the check_req.php endpoint. This flaw allows network-adjacent attackers to execute arbitrary code on the device without requiring any form of authentication. The failure to validate user input enables attackers to craft malicious requests, potentially leading to unauthorized access and control over the system, executed within the context of the www-data user.
Affected Version(s)
cPH2 2.0.4