Executive brief
ChargePoint Home Flex electric vehicle charging stations contain a security flaw where sensitive cryptographic information is hardcoded into the device's software. A remote attacker can exploit this to uncover stored credentials without needing a password. This could allow an unauthorized user to gain further access to the charging station, potentially compromising user data or device operations.
Technical details
An information disclosure vulnerability exists in the ChargePoint Home Flex CPH50 firmware due to the inclusion of sensitive information in the source code (CWE-540). Specifically, the 'genpw' script contains a hardcoded secret cryptographic seed value. A remote, unauthenticated attacker can leverage this seed to derive or disclose stored credentials on the device. This flaw was identified during Pwn2Own and is fixed in firmware version 5.5.4.22.
Affected products
- ChargePoint Home Flex CPH50 Firmware versions prior to 5.5.4.22
Timeline
- 2025-03-13: disclosed: Vulnerability reported to vendor during Pwn2Own
- 2026-03-16: patched: Coordinated public release of advisory and fix in version 5.5.4.22
- 2026-04-11: advisory: NVD advisory published