PT-2026-3752 · Everest · Everest

CVE-2025-68133

·

Publicado

2026-01-21

·

Atualizado

2026-02-06

CVSS v3.1

7.4

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions EVerest versions 2025.9.0 and below
Description EVerest is an EV charging software stack susceptible to a denial-of-service condition. An attacker can exhaust the operating system's memory, leading to the termination of the module and affecting all EVSE functionality. This occurs by initiating an unlimited number of TCP connections that do not proceed to ISO 15118-2 communication. The system starts a new thread for each incoming TCP or TLS socket connection before verification, and the verification process is overly permissive.
Recommendations Update to version 2025.10.0 or later.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68133
GHSA-MV3W-PP85-5H7C

Produtos afetados

Everest