CVE-2026-8980 Details
Description
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.
A privilege escalation vulnerability exists in the Mennekes Amtron series, specifically in firmware versions through 5.22.3. This vulnerability allows an authenticated low-privileged user to change the passwords of admin and manufacturer accounts by sending crafted POST requests. Successful exploitation could lead to unauthorized access and control over the charging infrastructure.
Users are advised to update to the latest firmware version. If an update is not available, access to the device should be restricted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cyberdanube.com/security-research/multiple-vulnerabilities-in-mennekes-amtron-series/ | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://cyberdanube.com/security-research/multiple-vulnerabilities-in-mennekes-amtron-series/ | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mennekes Amtron Professional | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amtron Professional Eichrecht | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amedio Professional | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amtron Charge Control | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amtron Professional Twincharge | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Smart-T PnC | <= 5.22.3 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion