PT-2026-3852 · Everest · Everest

CVE-2025-68139

·

Publicado

2026-01-21

·

Atualizado

2026-01-21

CVSS v3.1

4.3

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions EVerest versions up to and including 2025.12.1
Description EVerest is an EV charging software stack. By default, the terminate connection on failed response setting is set to False in all versions up to and including 2025.12.1. This configuration places the responsibility for session and connection termination on the EV. Errors encountered by the module are logged but do not trigger automatic session and connection reset or termination. This could potentially be exploited by a malicious user to take advantage of other weaknesses. The terminate connection on failed response variable controls this behavior.
Recommendations Change the terminate connection on failed response setting to true.

Exploit

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68139
GHSA-WQH4-PJ54-6XV9

Produtos afetados

Everest