PT-2025-24282 · Wolfbox · Wolfbox Level 2 Ev Charger

Published

2025-06-06

·

Updated

2025-08-14

·

CVE-2025-5747

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WOLFBOX Level 2 EV Charger (affected versions not specified)
Description This issue allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV Charger devices. The flaw exists within the handling of command frames received by the MCU, where the process does not properly detect the start of a frame, leading to misinterpretation of input. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Authentication is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-5747
ZDI-25-326

Affected Products

Wolfbox Level 2 Ev Charger