S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-46359 Scanner

CVE-2023-46359 Scanner - OS Command Injection vulnerability in cPH2 Charging Station

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-46359
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

The cPH2 Charging Station, developed by Hardy Barth, is widely used in the electric vehicle industry to manage and facilitate the scanning and demand of charge stations. Aimed at service providers, businesses, and residential users, it ensures efficient energy distribution. The software's robust interface supports different user capabilities and integrates seamlessly with various IT infrastructure systems, making it a choice for smart charging solutions. Its expansion options and connectivity with automation technologies provide efficient charging operations. By improving user interaction and energy management, it also supports eco-friendly initiatives.

The OS Command Injection vulnerability found in cPH2 Charging Station allows attackers to execute arbitrary commands on the host system. This critical flaw resides in the system's connectivity check feature, which lacks proper sanitization of input parameters, thus allowing arbitrary command execution. An unauthenticated attacker can leverage this to gain control over the system. This vulnerability threatens the integrity and availability of the charge station infrastructure. As attackers can execute system-level commands, it poses a severe risk.

Technically, the vulnerability is concentrated on a particular endpoint designed to verify system connections. An insecure handling of input in the ‘connectioncheck.php’ script allows attackers to append crafted arguments leading to remote command execution. The attack vector is primarily an unauthenticated remote request, exploiting improper input validation within the connectivity function. Using command concatenation techniques, attackers can manipulate responses by executing their commands. The endpoint's weak input filtering contributes to this exploitable vulnerability.

Attackers exploiting this flaw can achieve complete control over affected systems, possibly disrupting operations, exfiltrating sensitive data, or launching further attacks. Systems become vulnerable to data integrity breaches, loss of confidentiality, and service disruptions. Attackers could pivot from this access to other parts of a network, leading to more extensive organizational impacts. Losing control over the critical infrastructure of charging stations could result in both operational downtime and significant financial damages.

REFERENCES

Solution Advice
  • Upgrade to cPH2 Charging Station version 2.0.0 or later where the vulnerability is addressed.
  • Implement stringent input validation and command sanitization processes within the connectivity check feature.
  • Monitor charge station logs for any suspicious activity indicating possible exploitation attempts.
  • Educate users and IT staff on recognizing potential threats and safe operation practices.
  • Regularly audit and test systems for security vulnerabilities and enforce timely patch management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-46359 Scanner - OS Command Injection vulnerability in cPH2 Charging Station S4E