ZDI-25-328: (0Day) (Pwn2Own) WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of cryptographic keys used in vendor-specific encrypted communications. The issue results from the lack of proper initialization of a variable prior to accessing it. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2025-5749.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-328?
ZDI-25-328 has been classified as a critical vulnerability due to the ability of attackers to bypass authentication.
How do I fix ZDI-25-328?
To mitigate ZDI-25-328, update the WOLFBOX Level 2 EV Charger to the latest firmware version that addresses this vulnerability.
Who is affected by ZDI-25-328?
ZDI-25-328 affects installations of WOLFBOX Level 2 EV Charger devices.
What type of attacks can exploit ZDI-25-328?
ZDI-25-328 can be exploited by network-adjacent attackers who can bypass authentication without the need for credentials.
What is the impact of ZDI-25-328 on WOLFBOX Level 2 EV Charger devices?
The impact of ZDI-25-328 allows unauthorized access to functionalities of the WOLFBOX Level 2 EV Charger, posing potential security risks.