Wolfbox's vulnerability footprint centers on its Level 2 electric vehicle charging hardware and firmware, a narrowly scoped but operationally sensitive product line. The durable signal reflects low-level implementation weaknesses including exposed dangerous methods, heap-based buffer overflows, hard-coded credentials, and uninitialized variables—issues characteristic of embedded device firmware where memory safety and access control are foundational. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wolfbox over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5750HIGH WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers | Jun 6, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-5749HIGH WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentica | Jun 6, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-5748HIGH WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on a | Jun 6, 2025 | 8.0 | 23 | NO | NO |
CVE-2025-5747HIGH WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbit | Jun 6, 2025 | 8.0 | 23 | NO | NO |
CVE-2025-5751MEDIUM WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authenticati | Jun 6, 2025 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wolfbox.
Media articles that mention a CVE ID that affects a product developed by Wolfbox — matched by CVE ID, not by vendor name.