Authentication Bypass Vulnerability in WOLFBOX Level 2 EV Charger
CVE-2025-5749

6.3MEDIUM

Key Information:

Vendor

Wolfbox

Vendor
CVE Published:
6 June 2025

What is CVE-2025-5749?

The WOLFBOX Level 2 EV Charger features a vulnerability in its handling of cryptographic keys, which could allow network-adjacent attackers to bypass authentication without needing prior access. This issue arises from an uninitialized variable that affects how encrypted communications are managed within the device. Attackers exploiting this flaw could gain unauthorized access to the system, posing significant security risks. It is crucial for users of affected devices to implement security updates and strengthen their configurations to safeguard against potential exploits.

Affected Version(s)

Level 2 EV Charger 3.1.17 (main), 1.2.6 (MCU)

References

CVSS V3.0

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.