A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.

Project Subscriptions

Vendors Products
Siemens Subscribe
Heliox Flex 180 Kw Ev Charging Station Subscribe
Heliox Mobile Dc 40 Kw Ev Charging Station Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens heliox Flex 180 Kw Ev Charging Station
Siemens heliox Mobile Dc 40 Kw Ev Charging Station
Vendors & Products Siemens
Siemens heliox Flex 180 Kw Ev Charging Station
Siemens heliox Mobile Dc 40 Kw Ev Charging Station

Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.
Weaknesses CWE-923
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-03-10T16:41:10.032Z

Reserved: 2025-03-06T16:53:49.577Z

Link: CVE-2025-27769

cve-icon Vulnrichment

Updated: 2026-03-10T16:38:11.992Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-10T18:17:52.873

Modified: 2026-03-11T13:53:47.157

Link: CVE-2025-27769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-11T11:50:01Z

Weaknesses