The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://r.sec-consult.com/echarge |
|
History
Wed, 21 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 21 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data. | |
| Title | Missing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stations | |
| Weaknesses | CWE-306 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published: 2025-05-21T11:29:15.596Z
Updated: 2025-05-21T17:47:15.728Z
Reserved: 2025-03-07T06:46:34.309Z
Link: CVE-2025-27803
Updated: 2025-05-21T17:47:11.141Z
Status : Awaiting Analysis
Published: 2025-05-21T12:16:21.100
Modified: 2025-05-21T20:24:58.133
Link: CVE-2025-27803
No data.