Iocharger AC Model Chargers Command Injection Vulnerability Leading to Root Access

Vulnerability

A command injection vulnerability has been identified in Iocharger firmware for AC model chargers, affecting versions prior to 24120701. This vulnerability allows authenticated users to execute operating system commands as the root user on the charging station. The issue arises from improper neutralization of special elements used in commands, enabling command injection via a specific binary. While the vulnerability is not directly exposed through the web interface, it can be exploited by convincing a user with low privileges to send a crafted HTTP request. The impact of this vulnerability is critical, as it allows full control over the charging station, including the ability to add, modify, and delete files and services. Additionally, compromised devices could potentially be used to access restricted networks. Given that this vulnerability involves an electric vehicle charger handling significant power, there are potential safety implications.

Impact

Exploitation of this vulnerability leads to full root access on the affected charging station, allowing the attacker to execute arbitrary commands, manipulate files and services, and potentially disrupt the safe operation of the electric vehicle charger.

Remediation

Iocharger has released a firmware update version 24120701 that addresses this vulnerability. For chargers requiring version 25010801, which fixes additional vulnerabilities, owners should contact their distributor or Iocharger directly to obtain the updated firmware.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.