PT-2025-2661 · Iocharger · Iocharger

Frank Breedijk

+2

·

Published

2025-01-09

·

Updated

2025-01-09

·

CVE-2024-43660

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Iocharger firmware for AC model chargers versions prior to 24120701
Description The issue allows an attacker to download any file on the filesystem using the CGI script. This has a critical impact, as sensitive files such as /etc/shadow, the CGI script source code, or binaries and configuration files can be accessed. The attack can be executed over any network connection and requires authentication, but the level of authentication is irrelevant. The confidentiality of all files on the device can be compromised. While this device handles significant amounts of power, the attack in isolation does not have a safety impact. The attack can be automated.
Recommendations For Iocharger firmware for AC model chargers versions prior to 24120701, update to version 24120701 or later to resolve the issue. As a temporary workaround, consider restricting access to the CGI script to minimize the risk of exploitation. Avoid using the CGI script until the issue is resolved.

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43660

Affected Products

Iocharger