Description
The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files from the underlying OS.
Problem types
CWE-552 Files or Directories Accessible to External Parties
Product status
* (semver) before 2.15
Credits
Wilco van Beijnum
Harm van den Brink(DIVD)
Frank Breedijk (DIVD)
References
csirt.divd.nl/CVE-2025-22369
csirt.divd.nl/DIVD-2025-00003
www.mennekes.nl/...ium/Release_Notes_for_2.15_06.03.2025.pdf