Executive brief
Mennekes Amtron electric vehicle charging stations are vulnerable to a security flaw that allows unauthorized individuals to take control of the device. By sending a specifically formatted message over the network, an attacker can change the user account password without needing any existing credentials. This could lead to a complete takeover of the charging infrastructure, allowing attackers to disrupt service or modify device settings.
Technical details
The Mennekes Amtron series (firmware versions ≤ 5.22.3) contains an authentication bypass vulnerability in the web management interface. The flaw exists because the /operator/operator endpoint does not properly validate session state or credentials before processing password change requests. An unauthenticated remote attacker can exploit this by sending a crafted HTTP POST request containing the 'UserPwdPlain_custom' parameter. Successful exploitation allows the attacker to reset the user account password, leading to full administrative control over the charging station. The vulnerability was verified on multiple models including Amtron Professional, Amedio Professional, and Amtron Charge Control.
Affected products
- Mennekes Amtron Professional <= 5.22.3
- Mennekes Amtron Professional (Eichrecht) <= 5.22.3
- Mennekes Amedio Professional <= 5.22.3
- Mennekes Amtron Charge Control <= 5.22.3
- Mennekes Amtron Professional Twincharge <= 5.22.3
- Mennekes Smart-T PnC <= 5.22.3
Timeline
- 2025-02-24: other: Initial contact with vendor PSIRT
- 2025-02-25: other: Vulnerabilities acknowledged by vendor
- 2026-05-28: disclosed: Advisory published by CyberDanube