CVE-2025-22367
Mennekes smart/premium charges systems, Command injection in time setting
CVE | CVE-2025-22367 |
Title | Mennekes smart/premium charges systems, Command injection in time setting |
Credits |
-
Wilco van Beijnum (finder)
-
Harm van den Brink(DIVD) (analyst)
-
Frank Breedijk (DIVD) (analyst)
|
Affected products |
Product |
Affected |
Unaffected |
Unknown |
Mennekes Smart / Premium charging stations
|
>=
*
to
< 2.15
(semver)
|
|
|
|
everything else |
|
|
CVSS |
|
References |
|
Problem type(s) |
|
Impact(s) |
CAPEC-248 Command Injection
|
Date published
|
10 Mar 2025 14:00 UTC
|
Last modified
|
11 Mar 2025 13:40 UTC
|
Description
The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS.
JSON version.