SecAlerts
chargepoint logo

chargepoint

Security Risk Profile

61
/100
high

Security Risk Score

Comprehensive risk assessment based on 40 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 1, 2024 to present

40
Total CVEs
25
Critical+High
5
Exploited
20
Unpatched

Threat Assessment

Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
20
Critical/High
Risk Level
61/100
high
⚠️ 5 Active Exploits 6 Zero-Days

Severity Distribution

Critical
0
High
25
Medium
7
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
3
2
OS Command Injection
1
3
Buffer Overflow
1
4
Input Validation
1
5
Code Injection
1

Most Affected Products

1. ChargePoint Home Flex59
2. Autel MaxiCharger8
3. ChargePoint Home Flex Nema 14-50 Plug Firmware6
4. ChargePoint Home Flex Hardwired Firmware6
5. ChargePoint Home Flex Nema 6-50 Plug Firmware6

Recent Vulnerabilities

See more →
CVE-2026-4157
CVSS 7.5high

(Pwn2Own) ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability

4/11/2026🔧 No Patch
CVE-2026-4156
CVSS 7.5high

(Pwn2Own) ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability

4/11/2026🔧 No Patch
CVE-2026-4155
CVSS 7.5high

(Pwn2Own) ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability

4/11/2026🔧 No Patch
ZDI-26-197
CVSS 7.5high

(Pwn2Own) ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability

3/16/2026🔧 No Patch
ZDI-CAN-26338
CVSS 7.5high

ZDI-26-197: (Pwn2Own) ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability

3/16/2026🔧 No Patch
ZDI-26-196
CVSS 7.5high

(Pwn2Own) ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability

3/16/2026🔧 No Patch
ZDI-CAN-26339
CVSS 7.5high

ZDI-26-196: (Pwn2Own) ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability

3/16/2026🔧 No Patch
ZDI-CAN-26340
CVSS 7.5high

ZDI-26-195: (Pwn2Own) ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability

3/16/2026🔧 No Patch
ZDI-26-195
CVSS 7.5high

(Pwn2Own) ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability

3/16/2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/hackers-get-1-047-000-for-76-zero-days-at-pwn2own-automotive-2026/
unknown

Hackers get $1,047,000 for 76 zero-days at Pwn2Own Automotive 2026

1/23/2026⚠ Exploited⚡ Zero-Day🔧 No Patch

Monitor chargepoint in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.