Vulnerability record · CVE-2023-46359 · published 6 February 2024
CVE-2023-46359: Hardy Barth cPH2 eCharge charging station OS command injection
HHardy Barth · Cph2 Echarge Firmware
Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier contains an OS command injection flaw in its connectivity check feature. Crafted arguments passed to that feature let an unauthenticated remote attacker run arbitrary commands on the device. The CVSS 3.1 score is 9.8 (critical), reflecting full loss of confidentiality, integrity and availability.
Description
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus very high EPSS and public exploit references, make this an urgent remote code execution risk.
What it is
Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier contains an OS command injection flaw in its connectivity check feature. Crafted arguments passed to that feature let an unauthenticated remote attacker run arbitrary commands on the device. The CVSS 3.1 score is 9.8 (critical), reflecting full loss of confidentiality, integrity and availability.
Impact
An attacker gains arbitrary command execution on the charging station with the privileges of the vulnerable service, allowing full compromise of the device. That can expose data, alter device behavior and disrupt availability.
Attack surface
The flaw is reachable over the network via the connectivity check feature, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The description does not state which port or interface the feature listens on.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.87608, 99.75th percentile) and both references are tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Upgrade cPH2 eCharge Ladestation firmware beyond v1.87.0 to a vendor-fixed release; confirm the fixed version with Hardy Barth since the record does not name one.
- If patching cannot be done immediately, remove the device from direct internet exposure and restrict management/connectivity-check access to a trusted network segment.
- Block or filter traffic to the connectivity check feature at the network boundary until the device is patched.
- Monitor vendor advisories for updated firmware and re-check exposure after any patch.
- Treat the device as untrusted on the network: segment it and limit what it can reach.
Detection
- Review device and network logs for unexpected outbound connections or command-like strings sent to the connectivity check feature.
- Alert on anomalous processes or shell activity on the charging station if host-level telemetry is available.
- Hunt for scanning or probing of the connectivity check endpoint from untrusted sources.
- Correlate unusual device behavior or configuration changes with inbound requests to the charging station.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-46359 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46359), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.