CVE-2024-4622

HIGH

alpitronic Hypercharger - Auth Bypass

Title source: llm
STIX 2.1

Description

If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.

Scores

CVSS v4 8.3
EPSS 0.0047
EPSS Percentile 64.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1392
Status published
Products (1)
alpitronic/Hypercharger EV Charger all versions
Published May 15, 2024
Tracked Since Feb 18, 2026