CVE-2025-68137 is a critical integer overflow vulnerability affecting the EVerest EV charging software stack prior to version 2025.10.0. This flaw, occurring in the SdpPacket::parse_header() function, can lead to either an infinite loop or a stack buffer overflow due to incorrect length calculations. With a CVSS score of 8.3 (HIGH), it presents a significant risk as an adjacent network attack with high impact on confidentiality, integrity, and availability, despite high attack complexity. There is currently no evidence of active exploitation, nor are there public exploit modules available on platforms like Metasploit or ExploitDB. However, the vulnerability has garnered notable community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.10.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.