Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-4155— ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability

EPSS 0.38% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-4155

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the genpw script. The issue results from the inclusion of a secret cryptographic seed value within the script. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-26340.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
通过源代码导致的信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
ChargePoint Home Flex 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ChargePoint Home Flex是美国ChargePoint公司的一系列电动汽车充电设备。 ChargePoint Home Flex存在安全漏洞,该漏洞源于源代码中包含秘密加密种子值,可能导致信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ChargePointHome Flex 5.5.4.13 -

II. Public POCs for CVE-2026-4155

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4155

登录查看更多情报信息。

Same Patch Batch · ChargePoint · 2026-04-11 · 3 CVEs total

CVE-2026-4156ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulne
CVE-2026-4157ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-4155

No comments yet


Leave a comment