CVE Database
/

CVE-2025-48417

Back to search

CVE-2025-48417

Published: May 21, 2025

Modified: Nov 3, 2025

PUBLISHED

Description

The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin interface. The files are located in /etc/ssl (e.g. salia.local.crt, salia.local.key and salia.local.pem). There is no option to upload/configure custom TLS certificates.

VendorProductVersions

eCharge Hardy Barth

cPH2 / cPP2 charging stations

affected
<=2.2.0

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now