CVE-2025-5517
CVSS 6.8 MEDIUM: heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra… EPSS 0.3% (19th percentile).
Vulnerabilities · 111 days ago
A vulnerable ABB Terra AC charger is not just at risk of crashing. A crafted OCPP message can pollute heap memory, take remote control, and even trigger a flash write that alters firmware behavior, so a bad management-plane message can become a lasting compromise on the device itself.
CISA and ABB list affected Terra AC wallbox versions across UL40/80A, UL32A, MID/CE, and JP models, with fixes in 1.8.33 or 1.8.34 depending on the product. ABB also warns against unsafe mode over HTTP, because unencrypted CSMS-to-charger traffic widens the attack path beyond the charger and lets backend traffic be tampered with en route.
CVSS 6.8 MEDIUM: heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra… EPSS 0.3% (19th percentile).
1 source covering this story
ABB Terra AC Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.
Part of the PlainSec briefing for 2026-05-26