Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a critical vulnerability in the firmware update process of charging controller basemodules. Attackers could exploit this by remotely installing modified firmware without needing prior access, potentially leading to a full system compromise. The main concern is confirming the relevance and exposure of this technology within your environment.
- Modified firmware can take over charging controllers.
- Critical flaw impacts unattended remote device updates.
- Assess exposure and relevance of charging controllers.
Attack Path
How an attacker could exploit the issue
An attacker could remotely compromise a charging controller's basemodule by exploiting a flaw in its firmware update mechanism. This process lacks proper cryptographic signature verification, allowing an unauthenticated attacker to upload malicious firmware. Successful exploitation could lead to a complete takeover of the device's system.
- No authentication required for attack.
- Firmware update process is the trigger.
- Results in full system compromise.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote attacker could install modified firmware on the charging controller's basemodule. This is possible because the firmware update process only checks the CRC32 checksum, not a cryptographic signature. When supported, this could lead to full system compromise of the charging controller.
- Charging controller system data could be affected.
- Modified firmware could be installed remotely.
- Full system compromise of the charging controller.
Operational Fix
Recommended remediation, mitigation, and detection steps
Action for this vulnerability will likely involve teams responsible for operational technology (OT) infrastructure, specialized firmware management, and potentially network security. The first practical step is to identify all charging controller basemodules, determine their network exposure and criticality, and then assign ownership for remediation planning.
- OT Infrastructure and Firmware Teams own the issue.
- Verify network reachability and asset criticality.
- Plan firmware update or compensating controls.