← Vulnerability feed

Vulnerability record · CVE-2021-22821 · published 28 January 2022

CVE-2021-22821: Schneider-electric evlink city evc1s22p4 firmware server-side request forgery (ssrf) vulnerability

Schneider Electric · Evlink City Evc1s22p4 Firmware

A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network targets when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

8.6 CVSS 3.1 High EPSS 0.82% · top 44.4% CWE-918 · Server-side request forgery (SSRF)
8.6CVSS 3.1 base score, v2 5.0
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network targets when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22821 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22820Schneider-electric evlink city evc1s22p4 firmware insufficient session expiration vulnerabilityA CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked sessio…EPSS 1.1%9.8CVE-2021-22707Schneider EVlink charging stations use hard-coded credentialsEVlink City, Parking and Smart Wallbox charging stations contain hard-coded credentials (CWE-798) in all firmware versions prior to R8 V3.4.0.1. An a…EPSS 65%analysed9.8CVE-2021-22727Schneider-electric evlink city evc1s22p4 firmware vulnerabilityA CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …EPSS 1.4%9.8CVE-2021-22729Schneider-electric evlink city evc1s22p4 firmware hard-coded password vulnerabilityA CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (E…EPSS 1.8%9.8CVE-2021-22730Schneider-electric evlink city evc1s22p4 firmware hard-coded credentials vulnerabilityA CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…EPSS 1.4%8.1CVE-2021-22726Schneider-electric evlink city evc1s22p4 firmware server-side request forgery (ssrf) vulnerabilityA CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa…EPSS 1.00%7.5CVE-2021-22818Schneider-electric evlink city evc1s22p4 firmware improper restriction of authentication attempts vulnerabilityA CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to …EPSS 1.0%7.5CVE-2021-22774Schneider-electric evlink city evc1s22p4 firmware vulnerabilityA CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink …EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2021-22821), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.