ABB Charger Firmware Flaw Reaches Beyond App Crashes

The real problem is not an app crash. Bad field-length handling in ABB Terra AC Wallbox protocol traffic can corrupt charger memory and, in the worst case, let a third-party app alter firmware behavior on a deployed charger. That turns a validation bug into a device-integrity issue for the charging fleet. CISA and ABB map the issue to three CVEs: CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143. Affected products include ABB Terra AC wallbox (JP) versions <=1.8.33 and 1.8.36, with the vendor fix listed as Terra AC wallbox (JP) 1.8.36. This is a patch advisory, not an exploitation campaign. The risk is narrow but concrete: if charger-to-app communication is reachable, a malformed request can move from memory corruption to firmware tampering, and that matters long after the initial bug is known.

Part of the PlainSec briefing for 2026-05-22

Sources