Vestel AC Charger Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability in the Vestel AC Charger EVC04 model, specifically in version 3.75.0, allows unauthorized access to files containing sensitive information such as credentials. These credentials could be used to further compromise the device. The vulnerability arises from the charger being connected to an open internet network and using default web configuration interface credentials.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system information, including credentials, which could be used to gain control of the charger. Additionally, such exploitation may cause a denial-of-service or partial integrity loss, disrupting the charger's operations.

Remediation

Users are strongly advised to update the AC charger software to version 3.187 or any later version. For those using version 3.75.0, it is recommended to change the default login credentials and remove any documents that contain these credentials from the web. Vestel also suggests using secure methods like Virtual Private Networks (VPNs) for remote access and minimizing network exposure for control system devices.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.6
exploitability
6.3
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.