📦 Everest

by Linuxfoundation

🔍 What is Everest?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-68141

HIGH CVSS 7.4 Jan 21, 2026

A null pointer dereference vulnerability in EVerest EV charging software allows remote attackers to cause denial of service by sending specially crafted DC_ChargeLoopRes messages. This affects all EVe...

CVE-2025-68136

HIGH CVSS 7.4 Jan 21, 2026

This vulnerability in EVerest EV charging software allows attackers to cause denial of service through null pointer dereference when handling SDP requests. The issue affects EV charging stations runni...

CVE-2025-68137

HIGH CVSS 8.3 Jan 21, 2026

An integer overflow vulnerability in EVerest EV charging software allows attackers to trigger either infinite loops or stack buffer overflows by sending specially crafted packets. This affects all EVe...

CVE-2025-68134

HIGH CVSS 7.4 Jan 21, 2026

This vulnerability in EVerest EV charging software allows attackers to cause denial of service by triggering assertion failures that crash individual modules. When any module crashes, the manager shut...

CVE-2025-68133

HIGH CVSS 7.4 Jan 21, 2026

This vulnerability in EVerest EV charging software allows attackers to cause denial of service by exhausting system memory through unlimited TCP connections. Attackers can initiate connections that ne...

CVE-2026-23955

MEDIUM CVSS 4.2 Jan 21, 2026

This vulnerability in EVerest EV charging software allows malicious operators to read unintended memory regions (heap/stack) through pointer arithmetic errors in integer-to-string concatenation. It af...

CVE-2025-68139

MEDIUM CVSS 4.3 Jan 21, 2026

This vulnerability in EVerest EV charging software allows attackers to exploit other weaknesses by keeping connections alive despite errors. All EVerest installations using default configurations are ...

CVE-2025-68140

MEDIUM CVSS 4.3 Jan 21, 2026

This vulnerability allows attackers to bypass session validation in EVerest EV charging software by sending V2G messages with session ID 0 when no session is registered. This enables unauthorized MQTT...

CVE-2025-68135

MEDIUM CVSS 6.5 Jan 21, 2026

This vulnerability in EVerest EV charging software allows unhandled C++ exceptions in the TbdController loop to cause silent termination of the controller and its caller. This leads to denial of servi...

CVE-2025-68132

MEDIUM CVSS 4.6 Jan 21, 2026

This vulnerability in EVerest EV charging software allows attackers to crash the process by sending malformed SLIP frames via serial input. It affects systems using the DZG_GSH01 powermeter SLIP parse...