ZDI-CAN-21454: ZDI-24-1046: (0Day) ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability. The specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network.
Other sources
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.6. The following CVEs are assigned: CVE-2024-7391.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21454?
The severity of ZDI-CAN-21454 is critical due to potential sensitive information disclosure.
How do I fix ZDI-CAN-21454?
To fix ZDI-CAN-21454, update your ChargePoint Home Flex devices to the latest firmware version released by ChargePoint.
Who is affected by ZDI-CAN-21454?
ZDI-CAN-21454 affects users of ChargePoint Home Flex charging devices that have not been updated.
What kind of attack does ZDI-CAN-21454 enable?
ZDI-CAN-21454 enables network-adjacent attackers to disclose sensitive information on vulnerable installations.
Is user interaction required for ZDI-CAN-21454 exploitation?
Yes, ZDI-CAN-21454 requires user interaction to exploit the vulnerability.