S21sec Cyber Solutions by Thales
First CVE: Sep 29, 2025Active for: 1 year
15
CVEs Published
More CVEs Published than 35% of tracked CNAs
7.5
Avg CVEs / Year
More Avg CVEs / Year than 45% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by S21sec Cyber Solutions by Thales over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2025
9 months ago
Most Recent CVE
Jan 7, 2026
198 days ago
Top CVEs
All CVEs published by S21sec Cyber Solutions by Thales as a CNA, regardless of affected vendor or product.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64388CRITICAL Denial of service of the web server through specific requests to this protocol | Oct 31, 2025 | 9.2 | 30 | NO | NO |
CVE-2025-64385CRITICAL The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software.
Using the manufacturer's software, | Oct 31, 2025 | 9.2 | 30 | NO | NO |
CVE-2026-22542CRITICAL An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service. | Jan 7, 2026 | 9.2 | 28 | NO | NO |
CVE-2026-22540CRITICAL The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for | Jan 7, 2026 | 9.2 | 28 | NO | NO |
CVE-2026-22535HIGH An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the se | Jan 7, 2026 | 8.9 | 27 | NO | NO |
CVE-2026-22536HIGH The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions | Jan 7, 2026 | 8.6 | 26 | NO | NO |
CVE-2026-22544HIGH An attacker with a network connection could detect credentials in clear text. | Jan 7, 2026 | 8.7 | 25 | NO | NO |
CVE-2026-22541HIGH The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating cor | Jan 7, 2026 | 8.2 | 25 | NO | NO |
CVE-2025-64389HIGH The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol. | Oct 31, 2025 | 8.3 | 25 | NO | NO |
CVE-2025-64386HIGH The
equipment grants a JWT token for each connection in the timeline, but during an
active valid session, a hijacking of the token can be done. This will allow an
attacker with the | Oct 31, 2025 | 7.7 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA15 CVEs
33%
40%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (13.3%)
Network9 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (20.0%)
High0 (0.0%)
None12 (80.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by S21sec Cyber Solutions by Thales as a CNA.
Media Mentions
Media articles that mention a CVE ID published by S21sec Cyber Solutions by Thales as a CNA — matched by CVE ID, not by organization name.