Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7607 | The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS. | |
| Title | Mennekes smart/premium charges systems, Command injection in time setting | |
| Weaknesses | CWE-250 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-04-01T04:47:44.127Z
Reserved: 2025-01-03T14:56:05.686Z
Link: CVE-2025-22367
Updated: 2025-03-11T19:23:16.270Z
Status : Deferred
Published: 2025-03-11T14:15:24.480
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-22367
No data.
OpenCVE Enrichment
No data.
EUVD