Skip to the content.

CVE-2025-22368

Mennekes smart/premium charges systems, Command injection in sCU firmware update

CVE CVE-2025-22368
Title Mennekes smart/premium charges systems, Command injection in sCU firmware update
Credits
  • Wilco van Beijnum (finder)
  • Harm van den Brink(DIVD) (analyst)
  • Frank Breedijk (DIVD) (analyst)
Affected products
Product Affected Unaffected Unknown
Mennekes Smart / Premium charging stations >= * to < 2.15 (semver)
everything else
CVSS
Base score 8.7 - HIGH
Attack Vector NETWORK
Attack Complexity> LOW
Attack Requirements NONE
Privileges Required LOW
Confidentiality Impact
Vulnerable system HIGH Subsequent systems LOW
Integrity Impact
Vulnerable system HIGH Subsequent systems NONE
Availability Impact
Vulnerable system HIGH Subsequent systems NONE
Safety impact NEGLIGIBLE
Automatable YES
Recovery NOT_DEFINED
Value Density NOT_DEFINED
Vulnerability Response effort NOT_DEFINED
Provider Urgency NOT_DEFINED
References
Problem type(s)
Impact(s) CAPEC-248 Command Injection
Date published 10 Mar 2025 14:00 UTC
Last modified 11 Mar 2025 13:40 UTC

Description

The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS commands are improperly neutralized when certain fields are passed to the underlying OS.




JSON version.