CVE-2024-43662 – Iocharger AC Models Arbitrary File Upload
The .exe or .exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the user interface for uploading files is only shown to the iocadmin user. This issue affects Iocharger firmware for AC models before version 24120701. Likelihood: Moderate – An attacker will need to have […]
CVE-2024-43661 – “Iocharger AC Firmware Buffer Overflow – CGI Binary/Script Remote Denial of Service”
The .so library, which is used by , is vulnerable to a buffer overflow in the code that handles the deletion of certificates. This buffer overflow can be triggered by providing a long file path to the action of the .exe CGI binary or to the .sh CGI script. This binary or script will write […]
CVE-2024-43660 – Iocharger CGI File Read/Download Vulnerability
The CGI script .sh can be used to download any file on the filesystem. This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. Likelihood: High, but credentials required. Impact: Critical – The script can be used to download any file on the filesystem, including sensitive files such as /etc/shadow, the CGI script source […]
CVE-2024-43659 – “Iocharger AC Model Firmware Default Credentials Vulnerability”
After gaining access to the firmware of a charging station, a file at can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. The issue is addressed by requiring a mandatory password change on first […]
CVE-2024-43654 – Iocharger AC EV Charger Command Injection
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability in Iocharger firmware for AC models allows OS Command Injection as root This issue affects all Iocharger AC EV charger models on a firmware version before 25010801. Likelihood: Moderate – The binary does not seem to be used by the web interface, so […]
CVE-2024-43658 – Iocharger Home File Traversal and Deletion Vulnerability
Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary files This issue affects Iocharger firmware for AC model before firmware version 25010801. Likelihood: High, but requires authentication Impact: Critical – The vulnerability can be used to delete any file on the charging station, severely impacting the integrity […]
CVE-2024-43657 – Iocharger AC Charger Root Command Injection Vulnerability
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: High. However, the attacker will need a (low privilege) account to gain access to the action.exe CGI binary and upload the crafted firmware file, […]
CVE-2024-43656 – Iocharger AC Model Charger Command Injection Vulnerability
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – It might be difficult for an attacker to identify the file structure of the directory, and then modify the backup to add […]
CVE-2024-43655 – Iocharger AC Charger Root Command Injection Vulnerability
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – The attacker will first need to find the name of the script, and needs a (low privilege) account to gain access to […]
CVE-2024-43653 – “Iocharger AC Charger Command Injection Root Privilege Escalation”
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – The binary does not seem to be used by the web interface, so it might be more difficult to find. It seems […]