CVE-2021-22821
HIGHEVlink <R8 V3.4.0.2 - Server-Side Request Forgery via Charging Station Parameters
Title source: manualDescription
A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network targets when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-348-02
Scores
CVSS v3
8.6
EPSS
0.0019
EPSS Percentile
41.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Details
CWE
CWE-918
Status
published
Products (6)
schneider-electric/evlink_city_evc1s22p4_firmware
< 3.4.0.2
schneider-electric/evlink_city_evc1s7p4_firmware
< 3.4.0.2
schneider-electric/evlink_parking_evf2_firmware
< 3.4.0.2
schneider-electric/evlink_parking_evp2pe_firmware
< 3.4.0.2
schneider-electric/evlink_parking_evw2_firmware
< 3.4.0.2
schneider-electric/evlink_smart_wallbox_evb1a_firmware
< 3.4.0.2
Published
Jan 28, 2022
Tracked Since
Feb 18, 2026