FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Zephyr Project OCPP Client Stack Buffer Overflow CVE-2026-13214

A stack-based buffer overflow exists in the Zephyr Project RTOS OCPP client’s parse_getconfig_msg function (ocpp_j.c) affecting versions ≤4.4.1. The flaw occurs when processing a malformed Open Charge Point Protocol GetConfiguration message from a Charge Point Management System, allowing an unauthenticated remote attacker to overwrite the stack with an excessively long key parameter. Successful exploitation can trigger a denial‑of‑service or achieve remote code execution on resource‑constrained EV charging stations lacking robust memory protection. Immediate patching or mitigating network exposure is required to prevent compromise of EVSE infrastructure.


LINK COPIED TO CLIPBOARD