CVE-2025-22370: Mennekes Smart / Premium Charging Stations

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.

Affected products

  • Mennekes Smart / Premium Charging Stations: before 2.15 (fixed in 2.15)

Published 2025-03-11. Last modified 2026-06-17.