EVerest是EVerest开源的一个电动汽车充电桩的固件。 EVerest 2026.02.0之前版本存在安全漏洞,该漏洞源于CSMS执行RemoteStop后,EVSE可能通过EV的BCB切换返回PrepareCharging状态,从而绕过远程停止的不可逆性和操作计费安全控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EVerest | everest-core | < 2026.02.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-22790 | 8.8 HIGH | EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_pa |
| CVE-2026-22593 | 8.4 HIGH | EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing |
| CVE-2026-23995 | 8.4 HIGH | EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ |
| CVE-2026-33009 | 8.2 HIGH | EVerest: MQTT Switch-Phases Command Data Race Causing Charger State Corruptio |
| CVE-2026-26008 | 7.5 HIGH | EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferMod |
| CVE-2026-26074 | 7.0 HIGH | EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data race |
| CVE-2026-26073 | 5.9 MEDIUM | EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue |
| CVE-2026-27813 | 5.3 MEDIUM | EVerest has use-after-free in auth timeout timer via race condition |
| CVE-2026-33014 | 5.2 MEDIUM | EVerest has Delayed Authorization Response Bypasses Termination After RemoteStop |
| CVE-2026-29044 | 5.0 MEDIUM | EVerest: Charging Continues When WithdrawAuthorization Is Processed Before TransactionStar |
| CVE-2026-26070 | 4.6 MEDIUM | EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash |
| CVE-2026-26071 | 4.2 MEDIUM | EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Free |
| CVE-2026-27814 | 4.2 MEDIUM | EVerest EvseManager phase-switch path has unsynchronized shared-state access race conditio |
| CVE-2026-26072 | 4.2 MEDIUM | EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map |
| CVE-2026-27815 | EVerest: ISO15118 session_setup payment options overflow can corrupt EVSE state | |
| CVE-2026-27816 | EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE state | |
| CVE-2026-27828 | EVerest: ISO15118 session_setup use-after-free can crash EVSE process |
No comments yet