TL;DR

ChargePoint Home Flex devices have a critical info-disclosure flaw allowing unauthorized access to sensitive details without authentication.

What happened

['Vulnerability found that exposes sensitive information in ChargePoint Home Flex charging stations', 'Inclusion of sensitive data in source code']

Why it matters for ops

['Potential exposure of internal configurations and credentials to unauthorized users']

Mitigation

  • Update to the latest patched version
  • Isolate affected stations on a separate VLAN if possible

Action items

  • Contact ChargePoint for patch updates
  • Review and secure configurations of all affected charging stations

Detection IOCs

  • Unexpected network requests from or to affected devices seeking file paths or debugging information

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-195/