Executive brief
The Mennekes Amtron series of electric vehicle charging stations is affected by a security flaw that allows users with low-level access to take full control of the device. By sending a specially crafted request, an attacker can reset the passwords for administrative and manufacturer accounts. This could lead to a complete takeover of the charging infrastructure, allowing unauthorized configuration changes or service disruption.
Technical details
A privilege escalation vulnerability exists in the Mennekes Amtron series firmware (versions ≤ 5.22.3) due to improper privilege management (CWE-269). An authenticated attacker with low-privileged access can send a crafted JSON POST request to the '/json/settings.json' endpoint to overwrite the 'OperatorPwdPlain_custom' or 'ManufacturerPwd_custom' parameters. This allows the attacker to reset the passwords for the operator (admin) and manufacturer accounts without knowing the current credentials. Successful exploitation results in full administrative control over the charging station's configuration and operations. Users are advised to update to the latest firmware version or restrict network access to the device management interface.
Affected products
- Mennekes Amtron Professional <= 5.22.3
- Mennekes Amtron Professional (Eichrecht) <= 5.22.3
- Mennekes Amedio Professional <= 5.22.3
- Mennekes Amtron Charge Control <= 5.22.3
- Mennekes Amtron Professional Twincharge <= 5.22.3
- Mennekes Smart-T PnC <= 5.22.3
Timeline
- 2025-02-24: other: Researcher contacted Mennekes PSIRT
- 2025-02-25: other: Vulnerabilities acknowledged and forwarded to manufacturer (Bender)
- 2025-05-28: advisory: Advisory released by CyberDanube
- 2026-05-28: disclosed: CVE published to NVD