Remote Code Execution Vulnerability in eCharge Hardy Barth cPH2 Charging Stations
CVE-2025-3881
8.8HIGH
What is CVE-2025-3881?
The eCharge Hardy Barth cPH2 charging stations are affected by a command injection vulnerability in the handling of the 'ntp' parameter within the check_req.php endpoint. This flaw allows network-adjacent attackers to execute arbitrary code on the device without requiring any form of authentication. The failure to validate user input enables attackers to craft malicious requests, potentially leading to unauthorized access and control over the system, executed within the context of the www-data user.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cPH2 2.0.4
References
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
