Undocumented Credential Vulnerability in Web Interface of a Popular Software Product
CVE-2025-48414
6.5MEDIUM
What is CVE-2025-48414?
This vulnerability involves the presence of several scripts within the web interface that can be accessed via undocumented hard-coded credentials. These scripts grant access to extended administrative and debugging functionalities likely designed for development purposes. This inadvertently broadens the attack surface, potentially allowing unauthorized users to exploit these scripts, posing significant security risks to the system.
Affected Version(s)
cPH2 / cPP2 charging stations <=2.2.0