CVE-2026-22790 is a high-severity stack buffer overflow vulnerability (CWE-121) affecting the EVerest EV charging software stack, specifically versions prior to 2026.02.0. This flaw allows an unauthenticated attacker on the same network segment to achieve remote code execution by sending oversized SLAC payloads, which corrupt a fixed-size stack buffer. With a CVSS score of 8.8 (High), the vulnerability presents a significant risk due to its network-adjacent attack vector and potential for complete compromise. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.02.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.