Record summary

CVE-2021-22707 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 14, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 )

CVE ListEVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 )affected

Nuclei templates

1
ProjectDiscoveryCRITICALEVlink City < R8 V3.4.0.1 - Authentication BypassCVSS 9.8

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

Impact

Unauthenticated attackers can bypass authentication via hardcoded credentials and issue unauthorized administrative commands to the charging station web server, potentially disrupting charging operations or stealing sensitive data.

Remediation

Upgrade to EVlink City R8 V3.4.0.1 or later to fix the authentication bypass vulnerability.

WeaknessesCWE-798
Authorsritikchaddha, dorkerdevil
Template tagscve2021cveevlinkauth-bypassschneider-electricvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:schneider-electric:evlink_city_evc1s22p4_firmware:*:*:*:*:*:*:*:*
Shodan: title:"EVSE web interface"
Shodan: http.title:"evse web interface"
FOFA: title="EVSE web interface"
FOFA: title="evse web interface"
Google: intitle:"evse web interface"

Source: ProjectDiscovery

References

2