CVE-2026-4155
Information Disclosure via Sensitive Data in ChargePoint Home Flex genpw Script
Publication date: 2026-04-11
Last updated on: 2026-04-27
Assigner: Zero Day Initiative
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chargepoint | home_flex_cph50_firmware | to 5.5.4.22 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-540 | Source code on a web server or repository often contains sensitive information and should generally not be accessible to users. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-4155 is an information disclosure vulnerability in ChargePoint Home Flex charging stations. It occurs because the genpw script includes a secret cryptographic seed value directly in its source code.
This flaw allows remote attackers to access sensitive information without needing authentication or user interaction.
By exploiting this vulnerability, attackers can disclose stored credentials, which may lead to further compromise of the affected devices.
How can this vulnerability impact me? :
This vulnerability can have a significant impact by allowing remote attackers to disclose sensitive information such as stored credentials on ChargePoint Home Flex charging stations.
Since no authentication or user interaction is required, attackers can exploit this vulnerability easily over the network.
Disclosure of these credentials can lead to further compromise of the devices, potentially affecting the security and operation of the charging stations.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows remote attackers to disclose sensitive information, specifically stored credentials, without authentication. Such unauthorized disclosure of sensitive data can lead to non-compliance with data protection regulations like GDPR and HIPAA, which mandate the protection of personal and sensitive information.
By exposing secret cryptographic seed values and stored credentials, the affected ChargePoint Home Flex devices risk violating confidentiality requirements under these standards, potentially resulting in regulatory penalties or the need for breach notifications.