CVE-2026-0778
8.8Enel · JuiceBox 40
The Enel X JuiceBox 40 charging station contains a missing authentication vulnerability in its Telnet service, which allows network-adjacent attackers to achieve remote code execution.
Executive summary
A critical missing authentication vulnerability in the Enel X JuiceBox 40 Telnet service permits unauthenticated remote code execution by network-adjacent attackers.
Vulnerability
The vulnerability stems from a lack of authentication within the Telnet service, which listens on TCP port 2000 by default. An unauthenticated, network-adjacent attacker can connect to this port and execute arbitrary code with the privileges of the service account.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on charging infrastructure poses a severe risk to operational integrity and physical safety. With a CVSS score of 8.8, this flaw could lead to full system compromise, allowing attackers to manipulate charging parameters, disrupt service, or use the device as a pivot point into the local network.
Remediation
Immediate Action: Restrict access to the Telnet service on TCP port 2000 via network-level controls or firewalls immediately, as no official patch is currently confirmed.
Proactive Monitoring: Monitor network traffic for any unauthorized connections to TCP port 2000 and review device logs for suspicious command execution patterns.
Compensating Controls: Isolate affected charging stations within a dedicated VLAN and implement strict ingress filtering to ensure only authorized management systems can communicate with the device.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity of this remote code execution vulnerability, administrators must prioritize the isolation of affected JuiceBox 40 units from the public internet or untrusted network segments. Until a formal vendor patch is released, network-level access control remains the primary mechanism for preventing exploitation.