CVE-2025-24003Classic Buffer Overflow in Contact Charx Sec-3000

Severity
8.2HIGHNVD
EPSS
0.2%
top 63.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8

Description

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 3.9 | Impact: 4.2

Affected Packages8 packages

CVEListV5phoenix_contact/charx_sec-30000.0.01.6.5
CVEListV5phoenix_contact/charx_sec-30500.0.01.6.5
CVEListV5phoenix_contact/charx_sec-31000.0.01.6.5
CVEListV5phoenix_contact/charx_sec-31500.0.01.6.5

🔴Vulnerability Details

2
CVEList
MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations2025-07-08
GHSA
GHSA-q779-94w6-29cw: An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, r2025-07-08
CVE-2025-24003 — Classic Buffer Overflow | cvebase