Home

Description

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

PUBLISHED Reserved 2025-02-06 | Published 2025-07-08 | Updated 2025-07-22 | Assigner CERTVDE




HIGH: 8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-1188 Insecure Default Initialization of Resource

Product status

Default status
unaffected

0.0.0 (semver) before 1.7.3
affected

Default status
unaffected

0.0.0 (semver) before 1.7.3
affected

Default status
unaffected

0.0.0 (semver) before 1.7.3
affected

Default status
unaffected

0.0.0 (semver) before 1.7.3
affected

Credits

Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) finder

References

certvde.com/de/advisories/VDE-2025-019

cve.org (CVE-2025-25271)

nvd.nist.gov (CVE-2025-25271)

Download JSON