A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor or perform other administrative actions. Ultimately, this backdoor also allows arbitrary execution of OS commands.
CVE ID: CVE-2025-48415
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.2
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vendor: eCharge Hardy Barth
Product: cPH2 / cPP2 charging stations
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.68% (scored less or equal to compared to others)
EPSS Date: 2025-06-19 (when was this score calculated)