Executive brief
The Zephyr OCPP 1.6 client, used in connected charging points and EV infrastructure, fails to safely parse session identifiers received from the central system server. A malicious or compromised central system can send malformed messages that crash the charge point application, causing a denial of service that blocks charging operations until the device is manually restarted.
Technical details
The vulnerability is a NULL pointer dereference in ocpp_process_server_msg() (subsys/net/lib/ocpp/ocpp.c). The code calls atoi(strtok_r(uid, "-", &tmp)) without checking whether strtok_r() returned NULL; when the server-supplied uid field is empty or lacks the "-" delimiter, strtok_r() returns NULL and atoi(NULL) dereferences an invalid pointer. The uid field originates from untrusted network data parsed from JSON frames in ocpp_j.c. An attacker with network access to the OCPP connection (or an MITM on non-TLS ws:// connections) can trigger this without additional authentication. The impact is platform-conditional: on MMU/MPU systems or those with CONFIG_NULL_POINTER_EXCEPTION_DETECTION enabled, the NULL dereference faults and crashes the OCPP reader thread; on bare-metal targets where address 0 is readable, the fault is benign. The applied patch addresses only the first atoi() call; a second unguarded atoi() call in the same function remains vulnerable when the uid contains a first token but no second "-"-delimited token.
Affected products
- Zephyr Zephyr RTOS unspecified
Timeline
- 2026-08-25: disclosed