CVE-2026-4155
Received Received - Intake
Information Disclosure via Sensitive Data in ChargePoint Home Flex genpw Script

Publication date: 2026-04-11

Last updated on: 2026-04-27

Assigner: Zero Day Initiative

Description
ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the genpw script. The issue results from the inclusion of a secret cryptographic seed value within the script. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-26340.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-11
Last Modified
2026-04-27
Generated
2026-05-06
AI Q&A
2026-04-11
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
chargepoint home_flex_cph50_firmware to 5.5.4.22 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-540 Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-4155 is an information disclosure vulnerability in ChargePoint Home Flex charging stations. It occurs because the genpw script includes a secret cryptographic seed value directly in its source code.

This flaw allows remote attackers to access sensitive information without needing authentication or user interaction.

By exploiting this vulnerability, attackers can disclose stored credentials, which may lead to further compromise of the affected devices.


How can this vulnerability impact me? :

This vulnerability can have a significant impact by allowing remote attackers to disclose sensitive information such as stored credentials on ChargePoint Home Flex charging stations.

Since no authentication or user interaction is required, attackers can exploit this vulnerability easily over the network.

Disclosure of these credentials can lead to further compromise of the devices, potentially affecting the security and operation of the charging stations.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

This vulnerability allows remote attackers to disclose sensitive information, specifically stored credentials, without authentication. Such unauthorized disclosure of sensitive data can lead to non-compliance with data protection regulations like GDPR and HIPAA, which mandate the protection of personal and sensitive information.

By exposing secret cryptographic seed values and stored credentials, the affected ChargePoint Home Flex devices risk violating confidentiality requirements under these standards, potentially resulting in regulatory penalties or the need for breach notifications.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart