Home
HIGH: 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Description
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.
Problem types
CWE-1188 Insecure Default Initialization of Resource
Product status
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
Credits
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)
References
certvde.com/de/advisories/VDE-2025-019