Executive brief
ChargePoint Home Flex is a smart home electric vehicle (EV) charging station. A security vulnerability in its communication service allows an attacker on the same local network to take complete control of the charger without needing a password. This could allow an attacker to disrupt vehicle charging, access the device's operating system, or use the charger as a foothold to attack other devices on the home network.
Technical details
A command injection vulnerability exists in the revssh service of ChargePoint Home Flex EV chargers. The flaw is located within the handling of Open Charge Point Protocol (OCPP) messages, where the application fails to properly validate user-supplied strings before passing them to a system call. An unauthenticated attacker on the same local network (adjacent) can exploit this to execute arbitrary commands with root privileges. The vulnerability was identified during Pwn2Own and is addressed in firmware version 5.5.4.22.
Affected products
- ChargePoint Home Flex CPH50 firmware versions prior to 5.5.4.22
Timeline
- 2025-03-06: disclosed: Vulnerability reported to vendor
- 2026-03-16: patched: Fixed in CPH50 firmware version 5.5.4.22
- 2026-03-16: advisory: Coordinated public release of advisory by ZDI
- 2026-04-11: other: NVD publication date