Pwn2Own ChargePoint Home Flex Bug: Unauthenticated Command Injection in EV Charger Allows Root Access
A command injection vulnerability in the revssh service of ChargePoint Home Flex EV chargers, disclosed at Pwn2Own, allows unauthenticated network-adjacent attackers to execute arbitrary code as root via a crafted OCPP message.