CVE-2025-24003: MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24003?
CVE-2025-24003 is classified as a high severity vulnerability due to the potential for unauthorized remote access and denial-of-service.
How do I fix CVE-2025-24003?
To mitigate CVE-2025-24003, ensure that your EichrechtAgents software is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-24003?
CVE-2025-24003 affects charging stations that comply with the German Calibration Law, specifically those running EichrechtAgents.
What type of attack is possible with CVE-2025-24003?
CVE-2025-24003 allows unauthenticated remote attackers to exploit MQTT messages to perform out-of-bounds writes.
What are the potential consequences of CVE-2025-24003?
Exploitation of CVE-2025-24003 can lead to a loss of integrity for EichrechtAgents and potential denial-of-service for the affected charging stations.