CVE-2025-22370
Mennekes smart/premium charges systems, SQL Injection in web configuration interface
| CVE | CVE-2025-22370 |
| Title | Mennekes smart/premium charges systems, SQL Injection in web configuration interface |
| Credits |
|
| Affected products |
| Product |
Affected |
Unaffected |
Unknown |
|
Mennekes Smart / Premium charging stations
|
>=
*
to
< 2.15
(semver)
|
|
|
|
everything else |
|
|
| CVSS |
|
| References |
|
| Problem type(s) |
|
| Impact(s) |
CAPEC-66 SQL Injection
|
|
Date published
|
10 Mar 2025 14:00 UTC
|
|
Last modified
|
11 Mar 2025 13:40 UTC
|
Description
Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.
JSON version.