Iocharger
16 CVEs tracked since 2025. Since Jan 2025, none of them reached CISA KEV.
Iocharger CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-01 | 16 | 0 |
Products
The products that kept showing up in Iocharger's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Iocharger.
- CVE-2024-43654Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
- CVE-2024-43658Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.—
- CVE-2024-43651Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station—
- CVE-2024-43649Authenticated command injection via <redacted>.exe <redacted> parameter8.8
- CVE-2024-43648Authenticated command injection via <redacted>.exe <redacted> parameter8.8
- CVE-2024-43657When uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.8.8
- CVE-2024-43660Arbitrary file download using <redacted>.sh7.5
- CVE-2024-43652Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
- CVE-2024-43653Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station8.8
- CVE-2024-43661Buffer overflow in <redacted>.so leads to DoS of OCPP service9.8
- CVE-2024-43650Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station—
- CVE-2024-43656A backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.8.8
- CVE-2024-43659Plaintext default credentials in firmware7.2
- CVE-2024-43662Authenticated arbitrary file upload to /tmp/ and /tmp/upload/—
- CVE-2024-43655Any authenticated users can execute OS commands as root using the <redacted>.sh CGI script.—
The record
- Peak rank
- #48 in Jan 2025
- Busiest month shown
- Jan 2025, 16 CVEs
- Months with a KEV entry
- 0 since Jan 2025
- Monthly snapshots
- 1 since 2025