CVE-2025-24002: MQTT DoS Vulnerability in German EV Charging Stations
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24002?
CVE-2025-24002 has been classified as a denial-of-service vulnerability affecting specific Phoenix Contact charging stations.
How does CVE-2025-24002 affect charging stations?
CVE-2025-24002 allows an unauthenticated remote attacker to crash the service on affected charging stations using MQTT messages.
Which firmware versions are vulnerable in CVE-2025-24002?
CVE-2025-24002 affects Phoenix Contact Charx Sec-3000, Sec-3050, Sec-3100, and Sec-3150 firmware versions up to and including 1.6.5.
How can I mitigate the risk of CVE-2025-24002?
To mitigate CVE-2025-24002, upgrade the affected firmware to a version that is not vulnerable.
Is authentication required to exploit CVE-2025-24002?
No, CVE-2025-24002 can be exploited by unauthenticated remote attackers.