CVE-2026-4155

7.5

ChargePoint · Home Flex

The ChargePoint Home Flex charging station contains a vulnerability in the genpw script that allows unauthenticated remote attackers to disclose sensitive information, including stored credentials.

Executive summary

A critical information disclosure vulnerability in ChargePoint Home Flex charging stations allows unauthenticated remote attackers to extract sensitive credentials, posing a significant security risk.

Vulnerability

This flaw is caused by the inclusion of a secret cryptographic seed value within the genpw script, which is accessible to unauthenticated remote attackers. An adversary can leverage this exposure to recover sensitive information and stored credentials from the affected hardware.

Business impact

The ability for an unauthenticated attacker to remotely obtain credentials presents a severe risk of further unauthorized access to the charging infrastructure and associated network segments. With a CVSS score of 7.5, this high severity vulnerability could lead to significant data compromise and loss of administrative control over the affected devices.

Remediation

Immediate Action: Contact ChargePoint support or monitor the vendor advisory portal to obtain and apply the necessary security updates to address the credential exposure in the genpw script.

Proactive Monitoring: Review device access logs for unusual requests directed at the internal script endpoints and monitor for any signs of unauthorized configuration changes or lateral movement.

Compensating Controls: Isolate affected charging stations within a dedicated, restricted VLAN and employ network firewalls to limit incoming traffic to only authorized management IP addresses.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or weaponized code currently available for this vulnerability.

Analyst recommendation

Given the exposure of sensitive credentials, this vulnerability requires immediate attention. Security teams should prioritize patching the affected ChargePoint Home Flex units as soon as the vendor provides a resolution and implement strict network segmentation to minimize the attack surface until the update is applied.

More ChargePoint CVEs

Sources