High severity7.8NVD Advisory· Published Aug 1, 2025· Updated Apr 15, 2026
CVE-2025-54564
CVE-2025-54564
Description
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.