Hardy Barth manufactures electric vehicle charging infrastructure, with its vulnerability footprint centered on the CPH2 eCharge charging station product and its associated firmware. The observed disclosures reflect the embedded systems and operational-technology context of networked charging equipment. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hardy Barth over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46359CRITICAL An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the | Feb 6, 2024 | 9.8 | 87 | NO | YES |
CVE-2023-46360HIGH Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges. | Feb 6, 2024 | 8.8 | 31 | NO | NO |
CVE-2024-11666CRITICAL Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verif | Nov 24, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-3883HIGH eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected | May 22, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-3881HIGH eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on | May 22, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-11665HIGH Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affect | Nov 24, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-3882HIGH eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code | May 22, 2025 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hardy Barth.
Media articles that mention a CVE ID that affects a product developed by Hardy Barth — matched by CVE ID, not by vendor name.