Threats Tagged 'cve-2025-68139'
View all threats tagged with 'cve-2025-68139'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-68139'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-68139 is a session fixation vulnerability in the EVerest everest-core EV charging software stack affecting versions up to 2025.12.1. The default configuration does not terminate sessions or connections upon failed responses, allowing attackers to potentially exploit session management weaknesses. Although changing the setting to terminate connections on failure mitigates the issue, it is not enabled by default due to risks of causing ECU resets and vehicle charging unavailability. The vulnerability has a medium severity with a CVSS score of 4.3, indicating limited impact on confidentiality and integrity without affecting availability. No known exploits are reported in the wild. European EV charging infrastructure operators using EVerest software should carefully evaluate the trade-offs between security and operational stability. Mitigation involves enabling the terminate_connection_on_failed_response setting while preparing for possible vehicle ECU disruptions. Join the discussion | CVE Database V5 | 01/21/2026, 19:36:36 UTC Added: 01/21/2026, 19:50:56 UTC |
Showing 1 to 1 of 1 result