Junglewise Threat Intelligence

CVE-2026-13217: Zephyr OCPP client NULL pointer dereference in UID parsing

CVE-2026-13217 · Severity: medium · CVSS 5.9 · Published 2026-08-25

Vendors: Zephyr.

Executive brief

The Zephyr OCPP 1.6 client, used in connected charging points and EV infrastructure, fails to safely parse session identifiers received from the central system server. A malicious or compromised central system can send malformed messages that crash the charge point application, causing a denial of service that blocks charging operations until the device is manually restarted.

Technical details

The vulnerability is a NULL pointer dereference in ocpp_process_server_msg() (subsys/net/lib/ocpp/ocpp.c). The code calls atoi(strtok_r(uid, "-", &tmp)) without checking whether strtok_r() returned NULL; when the server-supplied uid field is empty or lacks the "-" delimiter, strtok_r() returns NULL and atoi(NULL) dereferences an invalid pointer. The uid field originates from untrusted network data parsed from JSON frames in ocpp_j.c. An attacker with network access to the OCPP connection (or an MITM on non-TLS ws:// connections) can trigger this without additional authentication. The impact is platform-conditional: on MMU/MPU systems or those with CONFIG_NULL_POINTER_EXCEPTION_DETECTION enabled, the NULL dereference faults and crashes the OCPP reader thread; on bare-metal targets where address 0 is readable, the fault is benign. The applied patch addresses only the first atoi() call; a second unguarded atoi() call in the same function remains vulnerable when the uid contains a first token but no second "-"-delimited token.

Affected products

  • Zephyr Zephyr RTOS unspecified

Timeline

  • 2026-08-25: disclosed