Missing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stations
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected products
eCharge Hardy Barth · cPH2 / cPP2 charging stations