Junglewise Threat Intelligence

CVE-2026-4156: ChargePoint Home Flex stack overflow in OCPP getpreq

CVE-2026-4156 · Severity: high · CVSS 7.5 · Published 2026-04-11

Technologies: Chargepoint Home Flex Cph50, Chargepoint Home Flex Cph50 Firmware. Vendors: Chargepoint.

Executive brief

A security vulnerability exists in ChargePoint Home Flex electric vehicle chargers, which are used for residential EV charging. An attacker on the same local network could exploit this flaw to take full control of the charger without needing a password. This could lead to unauthorized access to the device's functions, potential service disruption, or use of the charger as a foothold to attack other devices on the home network.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the ChargePoint Home Flex CPH50 firmware within the handling of Open Charge Point Protocol (OCPP) messages. The 'getpreq' component fails to properly validate the length of user-supplied data before copying it into a fixed-length stack buffer. A network-adjacent attacker can exploit this flaw without authentication to execute arbitrary code with root privileges. The vulnerability was addressed in firmware version 5.5.4.22.

Affected products

  • ChargePoint Home Flex CPH50 firmware versions prior to 5.5.4.22

Timeline

  • 2025-03-06: disclosed: Vulnerability reported to vendor via Pwn2Own
  • 2026-03-16: patched: Coordinated public release of advisory and fix in version 5.5.4.22
  • 2026-04-11: advisory: NVD publication date

References

Related threats