The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EVlink Home Smart all versions prior to 2.0.6.0.0
- Schneider Electric Schneider Charge all versions prior to 1.13.4
- Summary
- CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary.
- Remediation
- For already connected products, version 2.0.6.0.0 of EVlink Home Smart includes a fix for this vulnerability and has been deployed to automatically upgrade all charging stations connected to the Wiser application. Make sure the charging station is connected to the Wiser application to ensure the new version is downloaded and installed. For new installations, a fix for this vulnerability is enforced through eSetup commissioning application. The installed firmware version can be verified through Wiser application (refer to the settings page for the charging station).
