OS Command Injection Vulnerability in Schneider Electric Charging Station
CVE-2025-5743

7HIGH

Key Information:

Vendor
CVE Published:
10 June 2025

What is CVE-2025-5743?

An OS command injection vulnerability has been identified in Schneider Electric's Charging Station, permitting an authenticated user to modify configuration parameters on the web server. This flaw can be exploited to gain unauthorized remote control over the charging station. Proper validation and sanitization measures should be implemented to mitigate this security risk. Users are advised to review their configurations and apply security patches promptly.

Affected Version(s)

EVLink WallBox All Versions

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5743 : OS Command Injection Vulnerability in Schneider Electric Charging Station