Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7606 | The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS. | |
| Title | Mennekes smart/premium charges systems, Command injection in firmware upgrade | |
| Weaknesses | CWE-250 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-04-01T04:47:47.110Z
Reserved: 2025-01-03T14:56:05.685Z
Link: CVE-2025-22366
Updated: 2025-03-11T14:53:50.407Z
Status : Deferred
Published: 2025-03-11T14:15:24.313
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-22366
No data.
OpenCVE Enrichment
No data.
EUVD