← Vulnerability feed

Vulnerability record · CVE-2021-22707 · published 21 July 2021

CVE-2021-22707: Schneider EVlink charging stations use hard-coded credentials

Schneider Electric · Evlink City Evc1s22p4 Firmware

EVlink City, Parking and Smart Wallbox charging stations contain hard-coded credentials (CWE-798) in all firmware versions prior to R8 V3.4.0.1. An attacker who knows or extracts those credentials can authenticate to the charging station web server as an administrator. Because the credentials are fixed in firmware, they cannot be rotated by the operator and affect every unpatched unit.

9.8 CVSS 3.1 Critical EPSS 65% · top 0.8% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 10.0
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this an urgent exposure for any internet- or network-reachable EVlink unit.

What it is

EVlink City, Parking and Smart Wallbox charging stations contain hard-coded credentials (CWE-798) in all firmware versions prior to R8 V3.4.0.1. An attacker who knows or extracts those credentials can authenticate to the charging station web server as an administrator. Because the credentials are fixed in firmware, they cannot be rotated by the operator and affect every unpatched unit.

Impact

An attacker gains administrative access to the charging station web server and can issue unauthorized commands, potentially disrupting charging operations or altering device configuration.

Attack surface

Reachable over the network via the charging station web server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required to exploit the flaw.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.64612 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade all affected EVlink City, Parking and Smart Wallbox devices to firmware R8 V3.4.0.1 or later per Schneider Electric advisory SEVD-2021-194-06.
  • Isolate charging station web interfaces from untrusted networks and restrict management access to a dedicated, firewalled segment.
  • Change any default or shared administrative credentials where the product permits it, and audit for remaining hard-coded accounts.
  • Monitor vendor advisories for further firmware updates if R8 V3.4.0.1 does not fully remove the hard-coded credentials.

Detection

  • Monitor charging station web server logs for successful administrative logins from unexpected source IPs or at unusual times.
  • Alert on administrative command or configuration-change requests to the charging station web interface from outside the management network.
  • Baseline normal management traffic to EVlink devices and flag new or anomalous clients authenticating to the web server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22820Schneider-electric evlink city evc1s22p4 firmware insufficient session expiration vulnerabilityA CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked sessio…EPSS 1.1%9.8CVE-2021-22727Schneider-electric evlink city evc1s22p4 firmware vulnerabilityA CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …EPSS 1.4%9.8CVE-2021-22729Schneider-electric evlink city evc1s22p4 firmware hard-coded password vulnerabilityA CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (E…EPSS 1.8%9.8CVE-2021-22730Schneider-electric evlink city evc1s22p4 firmware hard-coded credentials vulnerabilityA CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…EPSS 1.4%8.6CVE-2021-22821Schneider-electric evlink city evc1s22p4 firmware server-side request forgery (ssrf) vulnerabilityA CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network t…EPSS 0.82%8.1CVE-2021-22726Schneider-electric evlink city evc1s22p4 firmware server-side request forgery (ssrf) vulnerabilityA CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa…EPSS 1.00%7.5CVE-2021-22818Schneider-electric evlink city evc1s22p4 firmware improper restriction of authentication attempts vulnerabilityA CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to …EPSS 1.0%7.5CVE-2021-22774Schneider-electric evlink city evc1s22p4 firmware vulnerabilityA CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink …EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2021-22707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.