Man-in-the-Middle Vulnerability in Salia's Web Interface
CVE-2025-48417

6.5MEDIUM

Key Information:

Vendor
CVE Published:
21 May 2025

What is CVE-2025-48417?

The Salia web interface contains a vulnerability that involves hard-coded certificate and private key information used for Transport Layer Security (TLS), which is embedded in the firmware. This configuration exposes the interface running on TCP port 443 to potential man-in-the-middle attacks. An attacker can exploit this flaw by utilizing the compromised private key included in the firmware update files, located at /etc/ssl, including files such as salia.local.crt, salia.local.key, and salia.local.pem. Moreover, the absence of a feature to upload or customize TLS certificates further exacerbates the risk, leaving users vulnerable to unauthorized access during administrative sessions.

Affected Version(s)

cPH2 / cPP2 charging stations <=2.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Viehböck | SEC Consult Vulnerability Lab
.