CVE-2025-5747
WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatons of WOLFBOX Level 2 EV Charger devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of command frames received by the MCU. When parsing frames, the process does not properly detect the start of a frame, which can lead to misinterpretation of input. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-26501.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.41%
- CWE
- CWE-115
- Published
- 2025-06-06
- Last modified
- 2026-03-13
Affected products
- WOLFBOX Level 2 EV Charger
Weakness type
Related vulnerabilities
- CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be...
- CVE-2026-17566 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
- CVE-2026-17351 — pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
- CVE-2026-12491 — Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
- CVE-2025-68113 — ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
- CVE-2025-55303 — Unauthorized third-party images in Astro’s _image endpoint
- CVE-2025-54584 — GitProxy is vulnerable to a packfile parsing exploit
- CVE-2025-5826 — Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability