Man-in-the-Middle Vulnerability in Salia's Web Interface
CVE-2025-48417
What is CVE-2025-48417?
The Salia web interface contains a vulnerability that involves hard-coded certificate and private key information used for Transport Layer Security (TLS), which is embedded in the firmware. This configuration exposes the interface running on TCP port 443 to potential man-in-the-middle attacks. An attacker can exploit this flaw by utilizing the compromised private key included in the firmware update files, located at /etc/ssl, including files such as salia.local.crt, salia.local.key, and salia.local.pem. Moreover, the absence of a feature to upload or customize TLS certificates further exacerbates the risk, leaving users vulnerable to unauthorized access during administrative sessions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cPH2 / cPP2 charging stations <=2.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
