If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface
protected by authentication. If the default credentials are not changed,
an attacker can use public knowledge to access the device as an
administrator.
Fixes

Solution

No solution given by the vendor.


Workaround

alpitronic recommends users change the default credentials for all charging devices. alpitronic advises that the interface should be connected only to internal segregated and access-controlled networks and not exposed to the public internet/web. When informed of these vulnerabilities, alpitronic, in conjunction with and/or on behalf of affected clients, disabled the interface on any exposed devices and all clients were contacted directly and reminded that the interface is not intended to be visible on the public Internet and that default passwords should be changed. alpitronic are also applying mitigations to all devices in the field and to new devices in production. New devices will come with unique passwords. Devices using the default password will be automatically assigned new unique passwords, or at first access if the device has not yet been installed. Devices with the default passwords already changed will not be affected. New passwords can be obtained by scanning the QR-Code inside the charger or in DMS portal hyperdoc. Contact Hypercharger support with any questions about newly assigned passwords.

History

Thu, 27 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 16:45:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-03-27T16:07:24.605Z

Reserved: 2024-05-07T19:41:26.741Z

Link: CVE-2024-4622

cve-icon Vulnrichment

Updated: 2025-03-27T16:07:24.605Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T17:15:16.010

Modified: 2025-03-27T16:15:27.163

Link: CVE-2024-4622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.