CVE-2025-27803 Details
Description
The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.
A vulnerability exists in eCharge Hardy Barth cPH2 and cPP2 charging stations running firmware version 2.2.0, due to the absence of authentication for the web interface and the MQTT server. This flaw allows an attacker with network access to gain immediate administrative rights, enabling them to execute arbitrary administrative tasks, reconfigure the devices, or potentially access sensitive information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2025CISA-ADP
Assessed May 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://r.sec-consult.com/echarge | SEC Consult Vulnerability Lab | AdvisoryBundleRemedy |
| http://seclists.org/fulldisclosure/2025/May/23 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| eCharge Hardy Barth cPH2 | 2.2.0 (semver) |
CPE
Remediation
| |
| eCharge Hardy Barth cPP2 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| May 21, 2025 | CVE Modified | CISA-ADP |
| May 21, 2025 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion