WOLFBOX Level 2 EV Charger Heap-Based Buffer Overflow Remote Code Execution Vulnerability

Vulnerability

A heap-based buffer overflow vulnerability allowing remote code execution has been identified in the WOLFBOX Level 2 EV Charger. This issue arises in the tuya_svc_devos_activate_result_parse function, where the secKey, localKey, stdTimeZone, and devId parameters are improperly validated before being copied to a fixed-length heap-based buffer. As a result, network-adjacent attackers can execute arbitrary code on the affected device without requiring authentication.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected device.

Remediation

The advisory suggests restricting interaction with the product as a mitigation strategy.

Added: Jun 6, 2025, 4:26 PM
Updated: Jun 6, 2025, 4:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.9
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.