CVE-2025-68134

7.4

EVerest · everest-core

A denial of service vulnerability exists in the EVerest charging software stack due to improper error handling using the assert function, which can crash the entire manager module.

Executive summary

The EVerest everest-core software is susceptible to a denial of service attack that can cause a complete system shutdown through improper error handling.

Vulnerability

This vulnerability involves improper input validation where the application uses the assert function to handle error states. An unauthenticated attacker can trigger this condition, causing the manager module to crash and subsequently terminate all connected EVSE modules.

Business impact

The exploitation of this flaw leads to a significant denial of service, which disrupts EV charging operations and impacts all users managed by the affected stack. With a CVSS score of 7.4, this vulnerability represents a high risk to service availability and operational continuity in charging infrastructure.

Remediation

Immediate Action: Update the EVerest everest-core software to version 2025.10.0 or later to resolve the improper assertion handling.

Proactive Monitoring: Monitor system logs for unexpected manager module terminations or frequent service restarts that may indicate attempted exploitation.

Compensating Controls: Implement network segmentation to restrict access to the charging stack management interface to trusted administrative networks only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for a complete service shutdown within critical charging infrastructure, administrators must prioritize the update to version 2025.10.0. Testing and deploying this patch is essential to maintain the availability and reliability of the EVerest software stack.

More EVerest CVEs

Sources