CVE-2025-54564
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.
Published 2025-08-01. Last modified 2026-06-17.