Impact
The vulnerability allows publicly exposing charging station authentication identifiers through web‑based mapping platforms. This results in sensitive information disclosure and could enable attackers to retrieve or use credentials for unauthorized access. The weakness corresponds to improper protection of credentials (CWE‑522).
Affected Systems
The affected product is ePower epower.ie. No specific vendor versions or product versions are listed, so all released versions may be susceptible. This could impact any organization that relies on ePower's charging station mapping feature for asset visibility.
Risk and Exploitability
The CVSS score of 6.9 translates to medium severity, and the EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not currently in CISA’s KEV catalog. Attackers can likely exploit it by simply browsing or scraping the public mapping pages to obtain the exposed authentication identifiers, which offers a straightforward attacker path with minimal prerequisites.
OpenCVE Enrichment