PT-2026-3850 · Everest · Everest

CVE-2025-68137

·

Publicado

2026-01-21

·

Atualizado

2026-01-23

CVSS v3.1

8.3

Alta

VetorAV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EVerest versions prior to 2025.10.0
Description EVerest is an EV charging software stack. An integer overflow in the SdpPacket::parse header() function can occur when processing data. Specifically, the current buffer length can be set to 7 after an 8-byte header has been read. This results in a negative value when calculating the remaining length to read, which is then interpreted as a large positive value due to the size t data type. This can lead to an infinite loop or a stack buffer overflow, depending on whether the connection is plain TCP or TLS.
Recommendations Versions prior to 2025.10.0 should be updated to version 2025.10.0 or later.

Exploit

Correção

Infinite Loop

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68137
GHSA-7QQ4-Q9R8-WC7W

Produtos afetados

Everest