Junglewise Threat Intelligence

CVE-2026-4155: ChargePoint Home Flex sensitive information disclosure in genpw script

CVE-2026-4155 · Severity: high · CVSS 7.5 · Published 2026-04-11

Technologies: Chargepoint Home Flex Cph50, Chargepoint Home Flex Cph50 Firmware. Vendors: Chargepoint.

Executive brief

ChargePoint Home Flex electric vehicle charging stations contain a security flaw where sensitive cryptographic information is hardcoded into the device's software. A remote attacker can exploit this to uncover stored credentials without needing a password. This could allow an unauthorized user to gain further access to the charging station, potentially compromising user data or device operations.

Technical details

An information disclosure vulnerability exists in the ChargePoint Home Flex CPH50 firmware due to the inclusion of sensitive information in the source code (CWE-540). Specifically, the 'genpw' script contains a hardcoded secret cryptographic seed value. A remote, unauthenticated attacker can leverage this seed to derive or disclose stored credentials on the device. This flaw was identified during Pwn2Own and is fixed in firmware version 5.5.4.22.

Affected products

  • ChargePoint Home Flex CPH50 Firmware versions prior to 5.5.4.22

Timeline

  • 2025-03-13: disclosed: Vulnerability reported to vendor during Pwn2Own
  • 2026-03-16: patched: Coordinated public release of advisory and fix in version 5.5.4.22
  • 2026-04-11: advisory: NVD advisory published

References

Related threats