CVE-2025-68134
7.4EVerest · everest-core
A denial of service vulnerability exists in the EVerest charging software stack due to improper error handling using the assert function, which can crash the entire manager module.
Executive summary
The EVerest everest-core software is susceptible to a denial of service attack that can cause a complete system shutdown through improper error handling.
Vulnerability
This vulnerability involves improper input validation where the application uses the assert function to handle error states. An unauthenticated attacker can trigger this condition, causing the manager module to crash and subsequently terminate all connected EVSE modules.
Business impact
The exploitation of this flaw leads to a significant denial of service, which disrupts EV charging operations and impacts all users managed by the affected stack. With a CVSS score of 7.4, this vulnerability represents a high risk to service availability and operational continuity in charging infrastructure.
Remediation
Immediate Action: Update the EVerest everest-core software to version 2025.10.0 or later to resolve the improper assertion handling.
Proactive Monitoring: Monitor system logs for unexpected manager module terminations or frequent service restarts that may indicate attempted exploitation.
Compensating Controls: Implement network segmentation to restrict access to the charging stack management interface to trusted administrative networks only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for a complete service shutdown within critical charging infrastructure, administrators must prioritize the update to version 2025.10.0. Testing and deploying this patch is essential to maintain the availability and reliability of the EVerest software stack.