ChargePoint Home Flex Command Injection Remote Code Execution Vulnerability
Vulnerability
A command injection vulnerability allowing network-adjacent attackers to execute arbitrary code has been identified in ChargePoint Home Flex charging stations. This issue arises in the wlanapp module, where user-supplied strings are not properly validated before being used in system calls. Exploitation of this vulnerability allows attackers to execute code with root privileges, and no authentication is required.
Impact
Exploitation of this vulnerability leads to unauthorized arbitrary code execution on the affected device, with the executed code running in the context of the root user.
Remediation
According to the vendor, this vulnerability was patched in April 2024.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
