Executive brief
The OCPP 1.6 client in Zephyr's networking library parses remote charging station commands sent over WebSocket. A malicious or compromised central station can send a specially crafted message that causes the client to read beyond allocated memory and potentially crash the device, leading to denial of service of the charging infrastructure integration.
Technical details
The vulnerability is a buffer over-read in parse_rpc_msg() and extract_string_field() functions within ocpp_j.c, caused by unsafe use of strncpy() followed by strchr() without proper NUL-termination. The strncpy function does not NUL-terminate when the source is 127+ bytes, allowing strchr to scan past the 128-byte destination buffer into adjacent stack memory. A related defect in extract_payload() permits unbounded strchr/strrchr operations on a potentially unterminated receive buffer. The attack vector is network-based: inbound WAMP RPC frames arrive over WebSocket from the OCPP central system server (commonly unencrypted ws://). A malicious or on-path attacker can send an RPC frame with a uid or action field of 127+ bytes without a closing quote to trigger the over-read. The primary impact is denial of service via faulting on unmapped pages or stack corruption via stray NUL writes. The fix replaces the manual parser with bounds-respecting json_mixed_arr_parse() and explicitly NUL-terminates extracted fields.
Affected products
- Zephyr RTOS <UNKNOWN>
Timeline
- 2026-08-02: disclosed