Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-22539 - QC 60/90/120 Plugin
As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.
CVE-2026-22539
CVE-2026-22544 - QC 60/90/120 Plugin
An attacker with a network connection could detect credentials in clear text.
CVE-2026-22544
CVE-2026-22543 - QC 60/90/120 Plugin
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials
CVE-2026-22543
CVE-2026-22535 - QC 60/90/120 Plugin
An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications
CVE-2026-22535
CVE-2026-22536 - QC 60/90/120 Plugin
The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions
CVE-2026-22536
CVE-2026-22537 - QC 60/90/120 Plugin
The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.
CVE-2026-22537
CVE-2026-22542 - QC 60/90/120 Plugin
An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.
CVE-2026-22542
CVE-2026-22541 - QC 60/90/120 Plugin
The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.
CVE-2026-22541
