CVE-2026-22100
Comnand injection in OCPP ReserveLogin message
| CVE | CVE-2026-22100 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Title | Comnand injection in OCPP ReserveLogin message | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Credits |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Affected products |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVSS |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| References |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Problem type(s) | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Date published | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Last modified | 16 Jul 2026 15:41 UTC | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.
JSON version.