CVE-2025-5741 Details
Description
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file reads from the charging station. The exploitation of this vulnerability does require an authenticated session of the web server.
A path traversal vulnerability has been identified in the Schneider Electric EVLink WallBox, all versions. This vulnerability allows authenticated users to read arbitrary files from the charging station. The issue arises from improper limitations on file path handling, which could be exploited by manipulating file paths during an authenticated session on the web server.
The EVLink WallBox has reached its end of life and is no longer supported. Customers are advised to upgrade to the EVLink Pro AC model. In the meantime, implement network segmentation and firewall rules to block unauthorized access to HTTP ports, choose strong passwords, and monitor access logs. For more information on cybersecurity best practices, refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2025CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-03.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric EVLink WallBox | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2025 | New CVE Received | [email protected] |
Volerion