Vulnerability Description
The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS commands are improperly neutralized when certain fields are passed to the underlying OS.
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2025-22368
- https://csirt.divd.nl/DIVD-2025-00003
- https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart
FAQ
What is CVE-2025-22368?
CVE-2025-22368 is a documented vulnerability. The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS commands are improperly neutralized when certain field...
How severe is CVE-2025-22368?
CVSS scoring is not yet available for CVE-2025-22368. Check NVD for updates.
Is there a patch for CVE-2025-22368?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.