Vulnerability record · CVE-2021-22707 · published 21 July 2021
CVE-2021-22707: Schneider EVlink charging stations use hard-coded credentials
Schneider Electric · Evlink City Evc1s22p4 Firmware
EVlink City, Parking and Smart Wallbox charging stations contain hard-coded credentials (CWE-798) in all firmware versions prior to R8 V3.4.0.1. An attacker who knows or extracts those credentials can authenticate to the charging station web server as an administrator. Because the credentials are fixed in firmware, they cannot be rotated by the operator and affect every unpatched unit.
Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this an urgent exposure for any internet- or network-reachable EVlink unit.
What it is
EVlink City, Parking and Smart Wallbox charging stations contain hard-coded credentials (CWE-798) in all firmware versions prior to R8 V3.4.0.1. An attacker who knows or extracts those credentials can authenticate to the charging station web server as an administrator. Because the credentials are fixed in firmware, they cannot be rotated by the operator and affect every unpatched unit.
Impact
An attacker gains administrative access to the charging station web server and can issue unauthorized commands, potentially disrupting charging operations or altering device configuration.
Attack surface
Reachable over the network via the charging station web server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required to exploit the flaw.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.64612 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Upgrade all affected EVlink City, Parking and Smart Wallbox devices to firmware R8 V3.4.0.1 or later per Schneider Electric advisory SEVD-2021-194-06.
- Isolate charging station web interfaces from untrusted networks and restrict management access to a dedicated, firewalled segment.
- Change any default or shared administrative credentials where the product permits it, and audit for remaining hard-coded accounts.
- Monitor vendor advisories for further firmware updates if R8 V3.4.0.1 does not fully remove the hard-coded credentials.
Detection
- Monitor charging station web server logs for successful administrative logins from unexpected source IPs or at unusual times.
- Alert on administrative command or configuration-change requests to the charging station web interface from outside the management network.
- Baseline normal management traffic to EVlink devices and flag new or anomalous clients authenticating to the web server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06 | Vendor Advisory |
| http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06 | Vendor Advisory |
Track CVE-2021-22707 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.