CVE-2026-4155Disclosure(chargepoint / home_flex_cph50)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch chargepoint home_flex_cph50 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the genpw script. The issue results from the inclusion of a secret cryptographic seed value within the script. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-26340.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-540

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • home_flex_cph50
  • home_flex_cph50_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-16); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
home_flex_cph50home_flex_cph50_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-16: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-03-16: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 103-1604-1904-21
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-04-191
General1
2026-04-211
Patch1
Full discourse3 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-195|CVE-2026-4155] (Pwn2Own) ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability (CVSS 7.5; Credit: Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)) https://www.zerodayinitiative.com/advisories/ZDI-26-195/

    Post summary

    ZeroDay Initiative has disclosed a ChargePoint Home Flex information disclosure vulnerability (CVE-2026-4155) with CVSS 7.5, credited to a Pwn2Own participant, but no exploit code, patch, or activity in the wild is mentioned.

    00040730
    5.4K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    #ALERT CVE-2026-4155 | CVSS 7.5 | ChargePoint Home Flex charging stations expose hardcoded cryptographic seed in genpw script, enabling credential disclosure. No auth required. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/gPnL6r2C4m

    Post summary

    This tweet reports CVE‑2026‑4155, a CVSS 7.5 flaw in ChargePoint Home Flex charging station firmware that exposes a hardcoded cryptographic seed, enabling credential disclosure without authentication, and urges users to apply patches immediately.

    0000042
    26 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4155 ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sen… https://www.cve.org/CVERecord?id=CVE-2026-4155

    Post summary

    The tweet announces CVE-2026-4155 as an information disclosure issue for ChargePoint Home Flex, providing only a basic description and a link to the CVE record.

    00000164
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWchargepointhome_flex_cph50---
OSchargepointhome_flex_cph50_firmware---

Explore more