CVE-2024-23921

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 863

Summary

CVE-2024-23921 is a newly disclosed vulnerability affecting ChargePoint Home Flex charging stations. This issue permits network-proximate attackers to execute arbitrary code on vulnerable installations without the need for authentication. The root cause of this vulnerability lies within the wlanapp module, where insufficient validation of user-supplied input is employed before executing a system call. Consequently, attackers can exploit this weakness to run code with root privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share