Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vendor has not yet released a patch or communicated a timeline for firmware updates.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16053 | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data. |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 21 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 21 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data. | |
| Title | Missing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stations | |
| Weaknesses | CWE-306 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2025-11-03T19:46:28.780Z
Reserved: 2025-03-07T06:46:34.309Z
Link: CVE-2025-27803
Updated: 2025-11-03T19:46:28.780Z
Status : Deferred
Published: 2025-05-21T12:16:21.100
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-27803
No data.
OpenCVE Enrichment
No data.
EUVD