CVE-2025-22366: Mennekes Smart / Premium Charging Stations

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS.

Affected products

  • Mennekes Smart / Premium Charging Stations: before 2.15 (fixed in 2.15)

Published 2025-03-11. Last modified 2026-06-17.