CVE-2026-22790
EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` afte
EVerest is an EV charging software stack. Prior to version 2026.02.0, HomeplugMessage::setup_payload trusts len after an assert.
in release builds the check is removed, so oversized SLAC payloads are memcpy'd into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from network-provided frames. Version 2026.02.0 contains a patch.
HIGH · CVSS 8.8
EPSS 0.00035
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0