CVE-2025-52263

8.0

Startcharge · Artemis AC Charger 7-22 kW

The Web Configuration module in Startcharge Artemis AC Charger 7-22 kW version 1.0.4 allows authenticated network-adjacent attackers to achieve arbitrary code execution via crafted firmware uploads.

Executive summary

A critical vulnerability in the Startcharge Artemis AC Charger allows authenticated attackers to execute arbitrary code through malicious firmware uploads.

Vulnerability

This vulnerability resides in the Web Configuration module of the device. It permits an authenticated, network-adjacent attacker to upload crafted firmware, resulting in full system compromise via arbitrary code execution.

Business impact

The ability for an attacker to execute arbitrary code on charging infrastructure poses a severe risk to operational integrity and safety. With a CVSS score of 8.0, this flaw could lead to complete device takeover, potentially enabling lateral movement into the broader facility network or the physical sabotage of charging operations.

Remediation

Immediate Action: Contact the vendor immediately to obtain and apply the necessary firmware update to address this vulnerability.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts to the Web Configuration interface and review system logs for unusual firmware upload activity.

Compensating Controls: Restrict access to the charger's web management interface to trusted administrative IP addresses only, and isolate the charger on a segmented VLAN to minimize network-adjacent exposure.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the researcher write-up referenced by the CVE record.

Analyst recommendation

Given the potential for arbitrary code execution and the availability of technical details regarding the exploit, this vulnerability should be treated with high urgency. Administrators must prioritize updating the firmware on all affected Artemis AC units and ensure that network-level access controls are strictly enforced to prevent unauthorized configuration changes.

Sources