iocharger
Unclassifiedunknown
Latest CVEs
The 11 most recently published vulnerabilities affecting iocharger.
- CVE-2024-43654Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
- CVE-2024-43661Buffer overflow in <redacted>.so leads to DoS of OCPP service9.8
- CVE-2024-43660Arbitrary file download using <redacted>.sh7.5
- CVE-2024-43657When uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.8.8
- CVE-2024-43653Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
- CVE-2024-43652Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
- CVE-2024-43649Authenticated command injection via <redacted>.exe <redacted> parameter8.8
- CVE-2024-43648Authenticated command injection via <redacted>.exe <redacted> parameter8.8
- CVE-2024-43663Buffer overflow vulnerabilities in CGI scripts lead to segfault9.8
- CVE-2024-43659Plaintext default credentials in firmware7.2
- CVE-2024-43656A backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.8.8