CVE-2025-24956
CVSS 3.1 Score 6.2 of 10 (medium)
Details
Summary
CVE-2025-24956 is a newly discovered vulnerability affecting OpenV2G (versions below V0.9.6). The EXI parsing feature in this software lacks a necessary length check when processing X509 serial numbers. Consequently, an attacker can exploit this oversight to induce a buffer overflow, resulting in memory corruption. This vulnerability poses a significant risk, as successful exploitation could lead to unintended code execution or denial-of-service attacks. Users are strongly advised to update their OpenV2G installations to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.