Garo manufactures a line of electric vehicle charging wallbox products spanning multiple hardware generations and firmware versions, a focused portfolio with significant embedded deployment. The observed vulnerability pattern concentrates around authentication and input-handling weaknesses—including cross-site scripting, command injection, hard-coded credentials, and missing authentication controls for critical functions—typical of networked embedded devices where web interfaces and firmware update mechanisms present an attack surface. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Garo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45876CRITICAL Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an comm | Mar 21, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-45878CRITICAL Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify informatio | Mar 21, 2022 | 9.1 | 28 | NO | NO |
CVE-2023-30399HIGH Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update package link via a man-in-the-middle attack | May 4, 2023 | 8.1 | 25 | NO | NO |
CVE-2021-45877CRITICAL Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain a | Mar 21, 2022 | 9.8 | 25 | NO | NO |
CVE-2024-1707MEDIUM A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown part of the file /index.jsp#settings of the component Softwa | Feb 21, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Garo.
Media articles that mention a CVE ID that affects a product developed by Garo — matched by CVE ID, not by vendor name.