PT-2025-22346 · Echarge Hardy Barth · Cph2 / Cpp2 Charging Stations
Published
2025-05-21
·
Updated
2025-05-21
·
CVE-2025-48417
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined.
Description
The issue concerns hard-coded TLS certificates and private keys in the firmware for the web interface, specifically on TCP port 443. An attacker can exploit this by using the private key to perform man-in-the-middle attacks against users of the admin interface. The affected files are located in /etc/ssl, including salia.local.crt, salia.local.key, and salia.local.pem. There is no option to configure custom TLS certificates, making the system vulnerable to such attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cph2 / Cpp2 Charging Stations