Schneider Electric EVLink WallBox
cpe:2.3:h:schneider-electric:evlink_charging_station:*:*:*:*:*:*:*, +1 more
An OS command injection vulnerability has been identified in the Schneider Electric EVLink WallBox, all versions. This vulnerability allows remote control over the charging station when an authenticated user modifies configuration parameters on the web server.
Exploitation of this vulnerability could lead to unauthorized remote control of the charging station.
The EVLink WallBox has reached its end of life and is no longer supported. Customers are advised to upgrade to the EVLink Pro AC. For those who continue to use the WallBox, it is recommended to implement network segmentation, block unauthorized access to HTTP ports, choose strong passwords, and change them periodically.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.