CVE-2018-7802
Description
A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in Schneider Electric EVLink Parking v3.2.0-12_v1 and earlier allows authenticated attackers to gain full web interface access.
Vulnerability
A SQL injection vulnerability exists in Schneider Electric EVLink Parking versions 3.2.0-12_v1 and prior. The flaw resides in the web interface component, where improper neutralization of special elements used in SQL commands allows an attacker to inject arbitrary SQL queries. This vulnerability is assigned CVE-2018-7802 and has a CVSS v3 base score of 6.4 (AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) [1].
Exploitation
An attacker must have low-privileged access to the device (e.g., a valid user account) to exploit this vulnerability. No user interaction is required. The attacker can send crafted SQL injection payloads to the vulnerable web interface, bypassing authentication or escalating privileges to gain full administrative access. The attack is remotely exploitable over the network [1].
Impact
Successful exploitation allows the attacker to access the web interface with full privileges, leading to low confidentiality and low integrity impacts. The scope of the compromise changes, meaning the attacker can affect resources beyond the vulnerable component. This could enable further attacks such as stopping the charging station or executing arbitrary commands, though those are covered by other CVEs [1].
Mitigation
Schneider Electric recommends users update to a fixed version. As of the advisory date (January 31, 2019), the vendor has not released a specific patch version; users should contact Schneider Electric support for mitigation guidance. No workaround is provided in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.2.0-12_v1
- Schneider Electric SE/EVLink Parking v3.2.0-12_v1 and earlierv5Range: EVLink Parking v3.2.0-12_v1 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/106807mitrevdb-entryx_refsource_BID
- ics-cert.us-cert.gov/advisories/ICSA-19-031-01mitrex_refsource_MISC
- www.schneider-electric.com/en/download/document/SEVD-2018-354-01/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.