CVE-2021-22707

CRITICAL EXPLOITED NUCLEI

Schneider-electric Evlink City Evc1s22p4 Firmware < r8_v3.4.0.1 - Hard-coded Credentials

Title source: rule

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

Nuclei Templates (1)

EVlink City < R8 V3.4.0.1 - Authentication Bypass
CRITICALVERIFIEDby ritikchaddha,dorkerdevil
Shodan: title:"EVSE web interface" || http.title:"evse web interface"
FOFA: title="EVSE web interface" || title="evse web interface"

Scores

CVSS v3 9.8
EPSS 0.9157
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-02-14
CWE
CWE-798
Status published
Products (6)
schneider-electric/evlink_city_evc1s22p4_firmware < r8_v3.4.0.1
schneider-electric/evlink_city_evc1s7p4_firmware < r8_v3.4.0.1
schneider-electric/evlink_parking_ev.2_firmware < r8_v3.4.0.1
schneider-electric/evlink_parking_evf2_firmware < r8_v3.4.0.1
schneider-electric/evlink_parking_evw2_firmware < r8_v3.4.0.1
schneider-electric/evlink_smart_wallbox_evb1a_firmware < r8_v3.4.0.1
Published Jul 21, 2021
Tracked Since Feb 18, 2026