Medium - CVE-2025-24002 - An unauthenticated remote attacker can use MQTT...
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations...
High - CVE-2025-24003 - An unauthenticated remote attacker can use MQTT...
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only...
Medium - CVE-2025-24004 - A physical attacker with access to the device...
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary...
High - CVE-2025-25268 - An unauthenticated adjacent attacker can modify...
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.
Medium - CVE-2025-41665 - An low privileged remote attacker can enforce...
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.