CRITICAL

CVE-2021-22707

CVSS v3

9.8

CRITICAL

EPSS Score

91.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

Technical details

Published
7/21/2021

Frequently asked questions

What is CVE-2021-22707?

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

Is CVE-2021-22707 actively exploited?

Active exploitation of CVE-2021-22707 has not been confirmed. The EPSS score is 91.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-22707?

CVE-2021-22707 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-22707 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.