CVE-2025-48417

CVE-2025-48417: Hard-Coded Certificate and Private Key for HTTPS Web Interface in eCharge Hardy Barth cPH2 / cPP2 charging stations

Vendor Echarge Hardy Barth
Product cPH2 / cPP2 charging stations
Weakness CWE-321
Published May 21, 2025
Last update November 3, 2025

CVSS base score

What the vulnerability does

01Description

The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin interface. The files are located in /etc/ssl (e.g. salia.local.crt, salia.local.key and salia.local.pem). There is no option to upload/configure custom TLS certificates.

Key dates

02Disclosure timeline

May 21, 2025 CVE published
November 3, 2025 Record updated