Authentication Bypass Vulnerability in WOLFBOX Level 2 EV Charger
CVE-2025-5749
What is CVE-2025-5749?
The WOLFBOX Level 2 EV Charger features a vulnerability in its handling of cryptographic keys, which could allow network-adjacent attackers to bypass authentication without needing prior access. This issue arises from an uninitialized variable that affects how encrypted communications are managed within the device. Attackers exploiting this flaw could gain unauthorized access to the system, posing significant security risks. It is crucial for users of affected devices to implement security updates and strengthen their configurations to safeguard against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Level 2 EV Charger 3.1.17 (main), 1.2.6 (MCU)
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
