VulDB • 3h
Zephyr Project OCPP Client Stack Buffer Overflow CVE-2026-13214
A stack-based buffer overflow exists in the Zephyr Project RTOS OCPP client’s parse_getconfig_msg function (ocpp_j.c) affecting versions ≤4.4.1. The flaw occurs when processing a malformed Open Charge Point Protocol GetConfiguration message from a Charge Point Management System, allowing an unauthenticated remote attacker to overwrite the stack with an excessively long key parameter. Successful exploitation can trigger a denial‑of‑service or achieve remote code execution on resource‑constrained EV charging stations lacking robust memory protection. Immediate patching or mitigating network exposure is required to prevent compromise of EVSE infrastructure.