CVE-2023-46359
9.8
CRITICAL · CVSS 3.1 · EPSS 87.6% (pctl 100)
Patch early
EPSS 87.6% — above the 10% action threshold.
Description
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 87.61% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2024-02-06 |
| Last modified | 2026-07-09 |
Affected (2)
| Vendor | Product |
|---|---|
| hardy-barth | cph2 echarge |
| hardy-barth | cph2 echarge firmware |
References
→ the Explorer · watch your stack · NVD