以下是该漏洞描述信息的中文翻译: 在 中,OCPP 1.6 客户端会从 消息的 字段重构会话句柄(session handle)和 PDU 标识符(PDU id)。在 函数中,代码调用了 ,但未检查 的返回值。当服务器提供的 为空或不包含 分隔符时, 返回 NULL,而 会解引用空指针,导致未定义行为。 该 源自网络数据:在 中, 函数会对通过 TCP/WebSocket 从 OCPP 中央系统接收到的帧进行 JSON 解析,并将由服务器控制的字符串复制到本地缓冲区。恶意或已被攻陷的中央系统,或者在非 TLS 协议
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 4.3.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 4.3.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13214 | 9.8 CRITICAL | Stack buffer overflow in OCPP GetConfiguration key parsing |
| CVE-2026-13215 | 6.8 MEDIUM | Zephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a cra |
| CVE-2026-13216 | 6.1 MEDIUM | Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied cap |
| CVE-2026-13478 | 5.5 MEDIUM | Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_count |
No comments yet