CVE-2023-46359
cPH2 Charging Station v1.87.0 - OS Command Injection
Record summary
CVE-2023-46359 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALcPH2 Charging Station v1.87.0 - OS Command InjectionCVSS 9.8
An OS command injection vulnerability in Hardy Barth cPH2 Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.
Impact
Unauthenticated attackers can exploit OS command injection through the connectivity check feature to execute arbitrary system commands and completely compromise cPH2 charging station installations.
Remediation
Fixed in version 2.0.0
Source: ProjectDiscovery