Iocharger AC Model Chargers Command Injection Vulnerability Leading to Root Access

Vulnerability

A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling unauthorized command execution. While the vulnerability is not directly exposed through the web interface, it can be exploited by users with low-privilege accounts who can send crafted HTTP requests or by manipulating the Iocharger Pedestal charging station binary.

Impact

Exploitation of this vulnerability grants full control over the affected charging station, allowing the attacker to arbitrarily add, modify, and delete files and services, all executed with root privileges.

Remediation

Iocharger has released a firmware update version 24120701 that addresses this vulnerability. For chargers requiring the 25010801 update, Iocharger has made distributors aware of the available firmware. Users should contact their distributor or Iocharger directly to obtain the updated firmware.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.