CVE-2025-68134 is a denial-of-service vulnerability affecting the EVerest EV charging software stack prior to version 2025.10.0. The flaw stems from the frequent use of the 'assert' function, causing module crashes that lead to the manager shutting down all other modules and exiting. This vulnerability is rated HIGH with a CVSS score of 7.4, indicating it can be exploited with low attack complexity over an adjacent network to achieve a high impact denial of service. There is currently no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.10.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.