Executive brief
ABB Terra AC Wallbox electric vehicle chargers are affected by multiple memory corruption vulnerabilities. An attacker with high-level access and physical proximity could potentially take remote control of the charger and modify its firmware. This could lead to unauthorized changes in charging behavior or permanent damage to the device's flash memory.
Technical details
The ABB Terra AC Wallbox (JP) contains multiple memory corruption vulnerabilities, including heap-based buffer overflows (CWE-122), stack-based buffer overflows (CWE-121), and classic buffer overflows (CWE-120). These issues stem from insufficient validation of field lengths in self-defined communication protocols and unexpected lengths in binary files or OCPP keys. An attacker with high privileges and adjacent network access (specifically via Bluetooth) can exploit these flaws to pollute memory. Successful exploitation could allow the attacker to perform write operations to flash memory and alter firmware behavior. The vulnerabilities are addressed in firmware version 1.8.36.
Affected products
- ABB Terra AC Wallbox (JP) <= 1.8.33, 1.8.36
CVE identifiers
- CVE-2025-10504
- CVE-2025-12142
- CVE-2025-12143
Timeline
- 2026-05-21: advisory: CISA published advisory ICSA-26-141-05
- 2026-05-21: patched: Firmware version 1.8.36 released to address the vulnerabilities