CVE-2024-43655
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – The attacker will first need to find the name of the script, and needs a (low privilege) account to gain access to the script, or convince a user with such access to execute a request to it. Impact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services. CVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and compromised devices can be used to pivot into networks that should potentially not be accessible (SC:L/SI:L/SA:H). Becuase this is an EV charger handing significant power, there is a potential safety impact (S:P). This attack can be automated (AU:Y).
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/S:P/AU:Y
- EPSS probability
- 1.21%
- CWE
- CWE-78, CWE-250
- Published
- 2025-01-09
- Last modified
- 2026-03-13
Affected products
- Iocharger Iocharger firmware for AC models
Weakness type
Related vulnerabilities
- CVE-2026-73694 — FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition
- CVE-2026-73693 — FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
- CVE-2026-65639 — OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a...
- CVE-2026-65638 — Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated...
- CVE-2026-81468 — Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special...
- CVE-2026-81467 — Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special...
- CVE-2026-64837 — ICEcoder through 8.1 OS Command Injection via lib/properties.php
- CVE-2026-88889 — Renovate before 44.14.7 Command Injection via distributionType