CVE-2026-33015

EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE can return to `PrepareCharging` via the EV's BCB toggle, allowing session restart. This breaks the irreversibility of remote stop and can bypass operational/billing/safety controls. Version 2026.02.0 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:*

History

31 Mar 2026, 14:20

Type Values Removed Values Added
CPE cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:*
First Time Linuxfoundation
Linuxfoundation everest
References () https://github.com/EVerest/EVerest/security/advisories/GHSA-pw9q-2287-cchc - () https://github.com/EVerest/EVerest/security/advisories/GHSA-pw9q-2287-cchc - Exploit, Vendor Advisory

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) EVerest es una pila de software de carga de vehículos eléctricos. Antes de la versión 2026.02.0, incluso inmediatamente después de que el CSMS realice un RemoteStop (StopTransaction), el EVSE puede volver a 'PrepareCharging' a través del interruptor BCB del VE, permitiendo el reinicio de la sesión. Esto rompe la irreversibilidad de la parada remota y puede eludir los controles operativos/de facturación/de seguridad. La versión 2026.02.0 contiene un parche.

26 Mar 2026, 18:16

Type Values Removed Values Added
References () https://github.com/EVerest/EVerest/security/advisories/GHSA-pw9q-2287-cchc - () https://github.com/EVerest/EVerest/security/advisories/GHSA-pw9q-2287-cchc -

26 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 17:16

Updated : 2026-03-31 14:20


NVD link : CVE-2026-33015

Mitre link : CVE-2026-33015

CVE.ORG link : CVE-2026-33015


JSON object : View

Products Affected

linuxfoundation

  • everest
CWE
CWE-863

Incorrect Authorization