cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-126399.html CVE-2025-27769
LOW
Siemens Heliox EV Charging Stations Improper Access Control via Charging Cable
Record summary
CVE-2025-27769 has a selected CVSS score of 2.4 (low).
Description
A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Heliox Flex 180 kW EV Charging StationBrowse Siemens / Heliox Flex 180 kW EV Charging StationDefault status: unknown | CVE List | Before F4.11.1 | affected |
Heliox Mobile DC 40 kW EV Charging StationBrowse Siemens / Heliox Mobile DC 40 kW EV Charging StationDefault status: unknown | CVE List | Before L4.10.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27769