CVE Tools

Iocharger

16 CVEs tracked since 2025. Since Jan 2025, none of them reached CISA KEV.

Iocharger CVEs per month

Jan 2025 to Jan 2025. Point at a month, or focus the strip and use the arrow keys.
Iocharger CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-01160

Products

The products that kept showing up in Iocharger's monthly top three, with their CVEs summed over those months.

  1. Iocharger Firmware For Ac Models151 month
  2. Iocharger Firmware For Ac Chargers11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Iocharger.

  1. CVE-2024-43654Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
  2. CVE-2024-43658Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.—
  3. CVE-2024-43651Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station—
  4. CVE-2024-43649Authenticated command injection via <redacted>.exe <redacted> parameter8.8
  5. CVE-2024-43648Authenticated command injection via <redacted>.exe <redacted> parameter8.8
  6. CVE-2024-43657When uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.8.8
  7. CVE-2024-43660Arbitrary file download using <redacted>.sh7.5
  8. CVE-2024-43652Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
  9. CVE-2024-43653Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
  10. CVE-2024-43661Buffer overflow in <redacted>.so leads to DoS of OCPP service9.8
  11. CVE-2024-43650Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station—
  12. CVE-2024-43656A backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.8.8
  13. CVE-2024-43659Plaintext default credentials in firmware7.2
  14. CVE-2024-43662Authenticated arbitrary file upload to /tmp/ and /tmp/upload/—
  15. CVE-2024-43655Any authenticated users can execute OS commands as root using the <redacted>.sh CGI script.—

The record

Peak rank
#48 in Jan 2025
Busiest month shown
Jan 2025, 16 CVEs
Months with a KEV entry
0 since Jan 2025
Monthly snapshots
1 since 2025
Iocharger's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store