5.3

CVE-2025-24002

MQTT DoS Vulnerability in German EV Charging Stations

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Charx Sec-3000 Firmware Version <= 1.6.5
   Phoenixcontact ≫ Charx Sec-3000 Version -
Phoenixcontact ≫ Charx Sec-3050 Firmware Version <= 1.6.5
   Phoenixcontact ≫ Charx Sec-3050 Version -
Phoenixcontact ≫ Charx Sec-3100 Firmware Version <= 1.6.5
   Phoenixcontact ≫ Charx Sec-3100 Version -
Phoenixcontact ≫ Charx Sec-3150 Firmware Version <= 1.6.5
   Phoenixcontact ≫ Charx Sec-3150 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.279
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://certvde.com/en/advisories/VDE-2025-014
Third Party Advisory