ChargePoint develops a focused line of home electric-vehicle charging hardware and firmware products, including its Home Flex series in multiple connector configurations. The recurring weakness classes in its disclosures center on input validation, buffer handling, certificate validation, and access control within embedded charging-device firmware, reflecting the challenges of securing networked power-delivery appliances. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chargepoint over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4157HIGH ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affect | Apr 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-4156HIGH ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code o | Apr 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-4155HIGH ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive infor | Apr 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-23921HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required | Jan 31, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-23920HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required | Jan 31, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-23971HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required | Jan 31, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-23969HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required | Jan 31, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-23968HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required | Jan 31, 2025 | 8.8 | 22 | NO | NO |
CVE-2024-23970MEDIUM This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not re | Jan 31, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-7392MEDIUM ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected | Nov 22, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chargepoint.
Media articles that mention a CVE ID that affects a product developed by Chargepoint — matched by CVE ID, not by vendor name.