Description
Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
OWASP-A03
Product status
* (semver) before 2.15
Credits
Wilco van Beijnum
Harm van den Brink(DIVD)
Frank Breedijk (DIVD)
References
csirt.divd.nl/CVE-2025-22370
csirt.divd.nl/DIVD-2025-00003
www.mennekes.nl/...ium/Release_Notes_for_2.15_06.03.2025.pdf