WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability

CVE Details

Basic Information

Title WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability
Type cve
Published 2025-06-06T15:29:51.274Z
Last Seen

Product Information

Vendor WOLFBOX
Product Level 2 EV Charger
Version 3.1.17 (main), 1.2.6 (MCU)

CVSS Information

Base Score 0.0 ()
Attack Vector
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description This vulnerability allows attackers to bypass authentication on WOLFBOX Level 2 EV Chargers by exploiting hard-coded credentials. It affects the management card handling due to a lack of personalization, enabling physical attackers to gain unauthorized access without needing authentication.
AI Severity Medium
Vendor WOLFBOX
Product WOLFBOX Level 2 EV Charger Management Card
Affected Version 3.1.17 (main), 1.2.6 (MCU)

Affected Products

  • WOLFBOX Level 2 EV Charger 3.1.17 (main), 1.2.6 (MCU)

Additional Information

CVE List
CWE List CWE-798
Bulletin Family

Description

WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of management cards. The issue results from the lack of personalization of management cards. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26292.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.