Vulnerability Description
Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2025-22370
- https://csirt.divd.nl/DIVD-2025-00003
- https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart
FAQ
What is CVE-2025-22370?
CVE-2025-22370 is a documented vulnerability. Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutra...
How severe is CVE-2025-22370?
CVSS scoring is not yet available for CVE-2025-22370. Check NVD for updates.
Is there a patch for CVE-2025-22370?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.