The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://r.sec-consult.com/echarge |
![]() ![]() |
History
Wed, 21 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 21 May 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data. | |
Title | Missing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stations | |
Weaknesses | CWE-306 | |
References |
|

Status: PUBLISHED
Assigner: SEC-VLab
Published: 2025-05-21T11:29:15.596Z
Updated: 2025-05-21T17:47:15.728Z
Reserved: 2025-03-07T06:46:34.309Z
Link: CVE-2025-27803

Updated: 2025-05-21T17:47:11.141Z

Status : Awaiting Analysis
Published: 2025-05-21T12:16:21.100
Modified: 2025-05-21T20:24:58.133
Link: CVE-2025-27803

No data.