CVE-2025-52268

7.5

StarCharge · Artemis AC Charger

StarCharge Artemis AC Charger version 1.0.4 contains a hardcoded AES key, allowing unauthenticated attackers to forge or decrypt valid login tokens.

Executive summary

A hardcoded cryptographic key in the StarCharge Artemis AC Charger allows unauthenticated attackers to bypass authentication and intercept or forge session tokens.

Vulnerability

The device utilizes a hardcoded AES key to manage authentication tokens. This flaw permits an unauthenticated remote attacker to generate valid session tokens or decrypt existing ones, effectively bypassing authentication mechanisms.

Business impact

The ability to forge authentication tokens presents a critical risk to the integrity and confidentiality of the charger management systems. An attacker could gain unauthorized administrative access to the device, potentially leading to unauthorized control over charging operations or the compromise of sensitive network data. With a CVSS score of 7.5, this vulnerability is classified as High severity due to the ease of exploitation over a network without requiring prior authentication.

Remediation

Immediate Action: Contact StarCharge support or monitor the official vendor security portal for firmware updates addressing the hardcoded key. If no patch is available, isolate the affected chargers from public-facing networks to prevent remote access.

Proactive Monitoring: Review device access logs for suspicious administrative logins or abnormal patterns in token validation requests.

Compensating Controls: Deploy a hardware firewall or implement strict network segmentation to restrict access to the charger management interface to authorized IP addresses only.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists, attributed to the research write-up linked in the CVE reference repository.

Analyst recommendation

Given the critical nature of hardcoded credentials, administrators must prioritize restricting network access to the affected hardware. While a specific firmware patch is not yet confirmed, organizations should engage with the vendor immediately to determine the upgrade path and ensure all devices are moved behind robust perimeter defenses to mitigate the risk of unauthorized remote exploitation.

Sources