CVE-2025-68136 is a null pointer dereference vulnerability affecting the EVerest EV charging software stack prior to version 2025.10.0. An attacker on the adjacent network can trigger this flaw by sending a crafted SDP request, causing the software to fail to properly manage connection objects and potentially leading to a denial of service. With a CVSS score of 7.4 (HIGH), this vulnerability has a low attack complexity and requires no user interaction, but its impact is limited to availability. There is currently no evidence of active exploitation, and no public exploit code is available, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.10.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.