PT-2026-3752 · Everest · Everest
Published
2026-01-21
·
Updated
2026-02-06
·
CVE-2025-68133
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
EVerest versions 2025.9.0 and below
Description
EVerest is an EV charging software stack susceptible to a denial-of-service condition. An attacker can exhaust the operating system's memory, leading to the termination of the module and affecting all EVSE functionality. This occurs by initiating an unlimited number of TCP connections that do not proceed to ISO 15118-2 communication. The system starts a new thread for each incoming TCP or TLS socket connection before verification, and the verification process is overly permissive.
Recommendations
Update to version 2025.10.0 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Everest