CVE-2025-12357 - CVE House
Back to Database
Status published Medium CVE-2025-12357

International Standards Organization ISO 15118-2 Improper Restriction of Communication Channel to Intended Endpoints

Vulnerability Description

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within close proximity, via electromagnetic induction.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12357

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mark I. Johnson of Southwest Research Institute reported this vulnerability to CISA.
  • Sébastien Dudek of Penthertz disclosed this vulnerability publicly.
  • Jean-Christophe Delaunay and Vincent Fargues of Synacktiv disclosed this vulnerability publicly.

Affected Vendor

ISO 15118-2 Network and Application Protocol Requirements

View all reports →

Affected Software

EV Car Chargers
Vulnerable Versions:
Part 15118-2 Network and Application Protocol Requirements

Timeline

Official Publish: October 31st, 2025
Last Modified: March 18th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.