CVE-2026-4156Disclosure(chargepoint / home_flex_cph50)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch chargepoint home_flex_cph50 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26339.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • home_flex_cph50
  • home_flex_cph50_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-16); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
home_flex_cph50home_flex_cph50_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-03-16: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 103-1603-1704-1904-21
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-03-171
Disclosure1
2026-04-191
Disclosure1
2026-04-211
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4156 ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi… https://www.cve.org/CVERecord?id=CVE-2026-4156

    Post summary

    The tweet announces CVE‑2026‑4156 as a stack‑based buffer overflow in ChargePoint Home Flex OCPP that enables remote code execution for network‑adjacent attackers.

    00010170
    57.2K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-196|CVE-2026-4156] (Pwn2Own) ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 7.5; Credit: Synacktiv) https://www.zerodayinitiative.com/advisories/ZDI-26-196/

    Post summary

    The advisory announces CVE-2026-4156 as a stack‑based buffer overflow in ChargePoint Home Flex’s OCPP getpreq handling, allowing RCE (CVSS 7.5), with Proof of Concept demonstrated in Pwn2Own.

    00010605
    5.4K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    #ALERT CVE-2026-4156 (CVSS 7.5) - ChargePoint Home Flex EV chargers vulnerable to unauthenticated RCE via OCPP stack buffer overflow. Network-adjacent attackers can execute code as root. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/rflUTTMxQ8

    Post summary

    The tweet highlights ChargePoint Home Flex EV chargers vulnerable to an unauthenticated RCE via an OCPP stack buffer overflow (CVSS 7.5) and urges users to patch immediately.

    0000055
    26 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for ChargePoint Home Flex (CVE-2026-4156) https://vuldb.com/?id.351347

    Post summary

    The post announces the disclosure of a new vulnerability (CVE-2026-4156) affecting ChargePoint Home Flex with an increased severity rating, but provides no further technical details or exploitation information.

    0000064
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWchargepointhome_flex_cph50---
OSchargepointhome_flex_cph50_firmware---

Explore more