Description
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.
Problem types
CWE-522 Insufficiently Protected Credentials
Product status
5.30.2 (semver) before 5.33.3
5.30.2 (semver) before 5.33.3
5.30.2 (semver) before 5.33.3
5.30.2 (semver) before 5.33.3
Credits
Dr. Matthias Kesenheimer by SySS GmbH
Sebastian Hamann by SySS GmbH
References
certvde.com/de/advisories/VDE-2025-061