CVE-2024-43662 – Iocharger AC Models Arbitrary File Upload

The .exe or .exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the user interface for uploading files is only shown to the iocadmin user. This issue affects Iocharger firmware for AC models before version 24120701. Likelihood: Moderate – An attacker will need to have […]

CVE-2024-43660 – Iocharger CGI File Read/Download Vulnerability

The CGI script .sh can be used to download any file on the filesystem. This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. Likelihood: High, but credentials required. Impact: Critical – The script can be used to download any file on the filesystem, including sensitive files such as /etc/shadow, the CGI script source […]

CVE-2024-43654 – Iocharger AC EV Charger Command Injection

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability in Iocharger firmware for AC models allows OS Command Injection as root This issue affects all Iocharger AC EV charger models on a firmware version before 25010801. Likelihood: Moderate – The binary does not seem to be used by the web interface, so […]

CVE-2024-43658 – Iocharger Home File Traversal and Deletion Vulnerability

Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary files This issue affects Iocharger firmware for AC model before firmware version 25010801. Likelihood: High, but requires authentication Impact: Critical – The vulnerability can be used to delete any file on the charging station, severely impacting the integrity […]

CVE-2024-43657 – Iocharger AC Charger Root Command Injection Vulnerability

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: High. However, the attacker will need a (low privilege) account to gain access to the action.exe CGI binary and upload the crafted firmware file, […]

CVE-2024-43656 – Iocharger AC Model Charger Command Injection Vulnerability

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – It might be difficult for an attacker to identify the file structure of the directory, and then modify the backup to add […]

CVE-2024-43655 – Iocharger AC Charger Root Command Injection Vulnerability

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – The attacker will first need to find the name of the script, and needs a (low privilege) account to gain access to […]

CVE-2024-43653 – “Iocharger AC Charger Command Injection Root Privilege Escalation”

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability  allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – The binary does not seem to be used by the web interface, so it might be more difficult to find. It seems […]