CVE-2025-24004: USB-C Buffer Overflow via Display Interface in EV Charging Stations
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24004?
CVE-2025-24004 has a medium severity rating due to potential integrity loss and temporary denial-of-service.
How do I fix CVE-2025-24004?
To mitigate CVE-2025-24004, upgrade the affected firmware to versions beyond 1.6.5 for the Phoenixcontact Charx Sec-3000 series.
Which devices are affected by CVE-2025-24004?
CVE-2025-24004 affects Phoenixcontact Charx Sec-3000, Sec-3050, Sec-3100, and Sec-3150 firmware versions up to 1.6.5.
What can an attacker do with CVE-2025-24004?
An attacker with physical access can trigger a buffer overflow, resulting in loss of integrity and causing a temporary denial-of-service.
Is CVE-2025-24004 exploitable remotely?
No, CVE-2025-24004 requires physical access to the device to be exploitable.