CVE-2025-54564

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.
Configurations

No configuration.

History

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) uploadsm en ChargePoint Home Flex 5.5.4.13 no valida una cadena controlada por el usuario para la descompresión bz2, lo que permite la ejecución del comando como usuario nobody.

01 Aug 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-20
CWE-77

01 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 18:15

Updated : 2025-08-04 15:06


NVD link : CVE-2025-54564

Mitre link : CVE-2025-54564

CVE.ORG link : CVE-2025-54564


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')