CVE-2025-68132 - CVE House
Back to Database
Status published Low CVE-2025-68132

EVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter driver

Vulnerability Description

EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[vec.size()-1]` and `vec[vec.size()-2]` without checking that at least two bytes are present. Malformed SLIP frames on the serial link can reach `is_message_crc_correct` with `vec.size() < 2` (only via the multi-message path), causing an out-of-bounds read before CRC verification and `pop_back` underflow. Therefore, an attacker controlling the serial input can reliably crash the process. Version 2025.12.0 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68132

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

everest-core
Vulnerable Versions:
< 2025.12.0

Timeline

Official Publish: January 21st, 2026
Last Modified: January 21st, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)