VYPR

Home Flex Nema 14 50 Plug Firmware

by Chargepoint

CVEs (6)

  • CVE-2024-23921HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanapp module. The issue…

  • CVE-2024-23920HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboardee module. The issue…

  • CVE-2024-23971HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The…

  • CVE-2024-23969HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue…

  • CVE-2024-23968HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg…

  • CVE-2024-23970MedJan 31, 2025
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST…