Charx Sec 3100 Firmware
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-3913 | Med | 0.38 | 5.9 | 0.01 | Aug 13, 2024 | An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup. | ||
| CVE-2024-26000 | Med | 0.38 | 5.9 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. | ||
| CVE-2024-25997 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected. | ||
| CVE-2024-25994 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only. | ||
| CVE-2025-24004 | Med | 0.34 | 5.2 | 0.00 | Jul 8, 2025 | A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog. | ||
| CVE-2025-24002 | Med | 0.34 | 5.3 | 0.00 | Jul 8, 2025 | An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog. | ||
| CVE-2024-25996 | Med | 0.34 | 5.3 | 0.00 | Mar 12, 2024 | An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user. | ||
| CVE-2024-28135 | Med | 0.33 | 5.0 | 0.01 | May 14, 2024 | A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected. | ||
| CVE-2024-26005 | Med | 0.31 | 4.8 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. |
- risk 0.38cvss 5.9epss 0.01
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
- risk 0.38cvss 5.9epss 0.01
An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
- risk 0.34cvss 5.2epss 0.00
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
- risk 0.33cvss 5.0epss 0.01
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
- risk 0.31cvss 4.8epss 0.01
An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.
Page 2 of 2