IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Hardy Barth Salia EV Charge Controller (Update A)

HIGH
CVSS 7.3
Date 2026-07-30T04:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could crash the device being accessed; a buffer overflow condition may allow remote code execution.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2025-10371 7.3 high
A security flaw has been discovered in eCharge Hardy Barth Salia PLCC 2.3.81. This issue affects some unknown processing of the file /api.php. The manipulation of the argument setrfidlist results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-5873 6.3 medium
A vulnerability was found in eCharge Hardy Barth Salia PLCC 2.3.81. It has been declared as critical. This vulnerability affects unknown code of the file /firmware.php of the component Web UI. The manipulation of the argument media leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

// Remediations (4)

Mitigation: Alternatively, Hardy Barth can also be contacted through their eCharge brand here: https://www.echar
Alternatively, Hardy Barth can also be contacted through their eCharge brand here: https://www.echarge.de/en/contact_company
Mitigation: Contact Hardy Barth using their contact page here: https://www.hardy-barth.de/de/kontakt for more in
Contact Hardy Barth using their contact page here: https://www.hardy-barth.de/de/kontakt for more information.
Mitigation: Furthermore, Hardy Barth has modified their firmware based web portal to eliminate direct unauthenti
Furthermore, Hardy Barth has modified their firmware based web portal to eliminate direct unauthenticated access to the web interface.
Mitigation: Hardy Barth has published the eCharge firmware version 2.4.0 which corrects CVE-2025-10371 (api.php)
Hardy Barth has published the eCharge firmware version 2.4.0 which corrects CVE-2025-10371 (api.php). and CVE-2025-5873 (firmware.php). The updated firmware is available here: https://firmware-download.echarge.de/. Note that authentication is required to access the firmware.

// References