The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EVLink WallBox All versions
- Summary
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes when an authenticated user on the web server manipulates file path.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: * Firewall configuration & logs: o Setup network segmentation and implement a firewall to block all unauthorized access to HTTP ports o Check the access log periodically * Password: o Choose a strong password o Do not share your password o Change your password periodically Customers should also consider upgrading to the replacement product offering EVLink Pro AC https://www.se.com/ww/en/product-range/23107242-evlink-pro-ac/#products to resolve these issues.
