Back

HIGH

ChargePoint Home Flex OCPP bswitch Command Injection

Published Jan 30, 2025

Description

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.

Affected products

Remediation

Vendor solution

The vendor states this vulnerability was patched in April 2024.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 30, 2025
Updated Aug 26, 2025
Reserved Jan 25, 2024
CISA Vulnrichment
Updated Jan 31, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a