[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgD6dEg6Xoy5PXB10DPr703HJwiI_Vl-0e64uROZpgn8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"2cc721fb-9ff4-48cf-b387-09d26cc6b3dd","critical-ev-charging-infrastructure-vulnerabilities-expose-remote-code-execution-risk","ad02fe72-5cc1-4b9e-a947-277beb3fe3da","Critical EV Charging Infrastructure Vulnerabilities Expose Remote Code Execution Risk","Two critical vulnerabilities in Hardy Barth Salia EV Charge Controllers allow attackers to upload malicious files through web endpoints, potentially enabling complete device takeover. The vendor's failure to respond to CISA coordination efforts and the availability of public exploits create an immediate security crisis for organizations using these devices. This incident highlights the critical importance of proactive vulnerability management for IoT and industrial control systems, especially when vendor support is unreliable. Organizations must implement defense-in-depth strategies to protect critical infrastructure components that may lack timely security updates.","**Immediate actions:**\n- Identify and inventory all Hardy Barth Salia EV Charge Controllers in your environment\n- Isolate affected devices from direct internet access using network segmentation\n- Monitor \u002Ffirmware.php and \u002Fapi.php endpoints for unauthorized file upload attempts\n\n**Long-term improvements:**\n- Establish automated vulnerability scanning for all IoT and industrial control devices\n- Implement vendor response time requirements in procurement contracts for critical infrastructure\n- Deploy web application firewalls to filter malicious file uploads on industrial systems\n\n**Risk mitigation:**\n- Create incident response procedures specific to compromised industrial control systems\n- Maintain offline backups of device configurations and firmware\n- Establish alternative charging infrastructure or manual processes as contingency plans",[12,13,14,15,16,17],"CIS Control 7","CIS Control 12","NIST SP 800-82","NIST CSF ID.AM-1","NIST CSF PR.IP-12","IEC 62443","published","2026-04-22T09:09:33.554518+00:00","2026-04-22T09:09:33.171+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-111-05","hardy-barth-salia-ev-charge-controller-dfef76","Hardy Barth Salia EV Charge Controller",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]