OT / ICS Security · IoT / OT Attack

ABB Charger Firmware Flaw Reaches Beyond App Crashes

The real problem is not an app crash. Bad field-length handling in ABB Terra AC Wallbox protocol traffic can corrupt charger memory and, in the worst case, let a third-party app alter firmware behavior on a deployed charger. That turns a validation bug into a device-integrity issue for the charging fleet.

CISA and ABB map the issue to three CVEs: CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143. Affected products include ABB Terra AC wallbox (JP) versions <=1.8.33 and 1.8.36, with the vendor fix listed as Terra AC wallbox (JP) 1.8.36.

This is a patch advisory, not an exploitation campaign. The risk is narrow but concrete: if charger-to-app communication is reachable, a malformed request can move from memory corruption to firmware tampering, and that matters long after the initial bug is known.

1 source · May 21

CVE-2025-10504

NVD KEV

CVSS 6.1 MEDIUM: heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33. EPSS 0.2% (11th percentile).

CVE-2025-12142

NVD KEV

CVSS 6.1 MEDIUM: buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This… EPSS 0.2% (10th percentile).

CVE-2025-12143

NVD KEV

CVSS 6.1 MEDIUM: stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33. EPSS 0.2% (10th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-21

Every edition of this story: ABB Charger Firmware Flaw Reaches Beyond App Crashes