Siemens Heliox EV Chargers
Siemens Heliox EV Chargers contain an improper access control vulnerability (CVE-2025-27769) that could allow attackers to reach unauthorized services via the charging cable. The vulnerability affects Heliox Flex 180 kW and Heliox Mobile DC 40 kW EV Charging Stations, with a CVSS score of 2.6 (LOW severity). Siemens recommends updating to the latest versions via OTA update and implementing proper network access controls.
Summary
Siemens Heliox EV Chargers contain an improper access control vulnerability (CVE-2025-27769) that could allow attackers to reach unauthorized services via the charging cable. The vulnerability affects Heliox Flex 180 kW and Heliox Mobile DC 40 kW EV Charging Stations, with a CVSS score of 2.6 (LOW severity). Siemens recommends updating to the latest versions via OTA update and implementing proper network access controls.
Indicators of Compromise
- cve — CVE-2025-27769