Description
The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
OWASP-A03
Product status
* (semver) before 2.15
Credits
Wilco van Beijnum
Harm van den Brink(DIVD)
Frank Breedijk (DIVD)
References
csirt.divd.nl/CVE-2025-22366
csirt.divd.nl/DIVD-2025-00003
www.mennekes.nl/...ium/Release_Notes_for_2.15_06.03.2025.pdf