CVE-2026-4157Disclosure(chargepoint / home_flex_cph50)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch chargepoint home_flex_cph50 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26338.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • home_flex_cph50
  • home_flex_cph50_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-16); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
home_flex_cph50home_flex_cph50_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-03-16: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 103-1603-1704-1904-21
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-03-171
General1
2026-04-191
Disclosure1
2026-04-211
Patch1
Full discourse4 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-4157 (CVSS 7.5) - ChargePoint Home Flex RCE via command injection in revssh service. No auth required. Network-adjacent attackers can execute arbitrary code as root. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/NoopqEwH3A

    Post summary

    High‑severity CVE‑2026‑4157 permits unauthenticated command injection on ChargePoint Home Flex revssh, allowing root code execution with no authentication; immediate patching is strongly advised.

    0000042
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4157 ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary co… https://www.cve.org/CVERecord?id=CVE-2026-4157

    Post summary

    The text announces CVE-2026-4157, a command injection flaw in ChargePoint Home Flex revssh service that could enable remote code execution; no PoC, exploit code, or patch details are provided.

    00000162
    57.2K followersView on X
  • VulDB 🛡@vuldb
    General

    A severe vulnerability was disclosed for ChargePoint Home Flex (CVE-2026-4157) https://vuldb.com/?id.351348

    Post summary

    The tweet reports the disclosure of CVE-2026-4157 for ChargePoint Home Flex but provides no further technical details or mitigation information.

    0000056
    2.1K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-197|CVE-2026-4157] (Pwn2Own) ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability (CVSS 7.5; Credit: Viettel Cyber Security) https://www.zerodayinitiative.com/advisories/ZDI-26-197/

    Post summary

    CVE-2026-4157 is a command injection Remote Code Execution vulnerability in ChargePoint Home Flex revssh service, disclosed with a CVSS score of 7.5 and link to a zero‑day advisory.

    00000636
    5.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWchargepointhome_flex_cph50---
OSchargepointhome_flex_cph50_firmware---

Explore more