CVE-2025-22370

Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Muchos campos de la interfaz de configuración web del firmware para Mennekes Smart / Premium Chargingpoints pueden ser utilizados de forma indebida para ejecutar comandos SQL arbitrarios porque los valores no están suficientemente neutralizados.

11 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 14:15

Updated : 2026-06-17 08:46


NVD link : CVE-2025-22370

Mitre link : CVE-2025-22370

CVE.ORG link : CVE-2025-22370


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')