HIGH
Mennekes smart/premium charges systems, Command injection in time setting
Published Mar 11, 2025
8.7
HIGHCVSS 4.0
EPSS 0.65%
Description
The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS.
Affected products
-
- Version -StatusaffectedConstraints<2.15
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mennekes | Smart / Premium charging stations | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://csirt.divd.nl/CVE-2025-22367 third-party-advisory
- https://csirt.divd.nl/DIVD-2025-00003 vendor-advisory
- https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf release-notes
| Link | Providers | Tags |
|---|---|---|
| https://csirt.divd.nl/CVE-2025-22367 | third-party-advisory | |
| https://csirt.divd.nl/DIVD-2025-00003 | vendor-advisory | |
| https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf | release-notes |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DIVD
Published Mar 11, 2025
Updated Apr 1, 2025
Reserved Jan 3, 2025
Link CVE-2025-22367
CISA Vulnrichment
Updated Mar 11, 2025