CVE-2025-68133
HIGH EPSS 27.0%
Published Jan 21, 20265mo ago · Modified Jun 17, 20262w ago
7.4 CVSS 3.1
Published Jan 21, 2026 5mo ago
Last Modified Jun 17, 2026 2w ago
Description
EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module to terminate by initiating an unlimited number of TCP connections that never proceed to ISO 15118-2 communication. This is possible because a new thread is started for each incoming plain TCP or TLS socket connection before any verification occurs, and the verification performed is too permissive. The EVerest processes and all its modules shut down, affecting all EVSE functionality. This issue is fixed in version 2025.10.0.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Attack Vector Adjacent
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Changed
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
27.0% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-770
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| linuxfoundation | everest | * | <2025.10.0 |
References 3
- github.com https://github.com/EVerest/everest-core/commit/8127b8c54b296c4dd01b356ac26763f81f76a8fd
- github.com https://github.com/EVerest/everest-core/commit/de504f0c11069010d26767b0952739e9a400cef3
- github.com https://github.com/EVerest/everest-core/security/advisories/GHSA-mv3w-pp85-5h7c
Remediation
- github.com https://github.com/EVerest/everest-core/commit/8127b8c54b296c4dd01b356ac26763f81f76a8fd
- github.com https://github.com/EVerest/everest-core/commit/de504f0c11069010d26767b0952739e9a400cef3