CVE-2026-4156 is a stack-based buffer overflow vulnerability affecting ChargePoint Home Flex EV chargers that stems from improper validation of OCPP message length fields. The flaw allows network-adjacent attackers to execute arbitrary code with root privileges without requiring authentication. This vulnerability was originally tracked as ZDI-CAN-26339 and represents a critical weakness in the charger's message handling implementation. The vulnerability carries a CVSS 3.0 score of 7.5 (HIGH) with an adjacent network attack vector, high complexity, and no privilege requirements. Successful exploitation could result in complete compromise of affected chargers, granting attackers high-impact capabilities across confidentiality, integrity, and availability. The EPSS score of 0.0008 indicates relatively low probability of exploitation relative to other CVEs, though this does not diminish the severity if targeted. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. No public exploit code is readily available, and community attention remains limited. Organizations operating ChargePoint Home Flex installations should treat this as a moderate-priority vulnerability requiring patch deployment, though the imminent risk of widespread attacks appears low at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5.4.22CPE matchmatch criteria | cpe:2.3:o:chargepoint:home_flex_cph50_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.