The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 21 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 21 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data. | |
| Title | Missing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stations | |
| Weaknesses | CWE-306 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published: 2025-05-21T11:29:15.596Z
Updated: 2025-11-03T19:46:28.780Z
Reserved: 2025-03-07T06:46:34.309Z
Link: CVE-2025-27803
Updated: 2025-11-03T19:46:28.780Z
Status : Awaiting Analysis
Published: 2025-05-21T12:16:21.100
Modified: 2025-11-03T20:18:07.377
Link: CVE-2025-27803
No data.