CVE-2025-22368

HIGH

Mennekes Smart/Premium - Command Injection

Title source: llm
STIX 2.1

Description

The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS commands are improperly neutralized when certain fields are passed to the underlying OS.

Scores

CVSS v4 8.7
EPSS 0.0036
EPSS Percentile 58.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/S:N/AU:Y

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-250 CWE-78
Status published
Products (1)
Mennekes/Smart / Premium charging stations < 2.15
Published Mar 11, 2025
Tracked Since Feb 18, 2026