Executive Summary
In September 2025, ABB identified multiple buffer overflow vulnerabilities in its Terra AC Wallbox electric vehicle chargers, specifically affecting firmware versions up to 1.8.33. These vulnerabilities, cataloged as CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143, could allow attackers with adjacent network access and high privileges to execute arbitrary code, potentially leading to unauthorized control over the device. ABB promptly released firmware version 1.8.36 to address these issues and recommended immediate updates to mitigate potential risks.
The discovery of these vulnerabilities underscores the critical importance of securing IoT devices, especially those connected to critical infrastructure like energy distribution. As the adoption of electric vehicle chargers grows, ensuring robust cybersecurity measures is essential to prevent potential exploitation that could disrupt services and compromise user safety.
Why This Matters Now
The increasing integration of IoT devices in critical infrastructure highlights the urgent need for proactive cybersecurity measures to prevent potential exploits that could disrupt essential services and compromise user safety.
Attack Path Analysis
An attacker exploited buffer overflow vulnerabilities in the ABB Terra AC Wallbox firmware via Bluetooth communication, leading to unauthorized code execution and potential firmware manipulation.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) in the ABB Terra AC Wallbox firmware through Bluetooth communication, leading to unauthorized code execution.
Related CVEs
CVE-2025-10504
CVSS 6.1A heap-based buffer overflow vulnerability in ABB Terra AC Wallbox firmware versions through 1.8.33 allows an attacker to corrupt heap memory, potentially leading to remote control of the device and unauthorized firmware modification.
Affected Products:
ABB Terra AC Wallbox – <= 1.8.33
Exploit Status:
no public exploitCVE-2025-12142
CVSS 6.1A buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in ABB Terra AC Wallbox firmware versions through 1.8.33 allows an attacker to corrupt BSS memory, potentially leading to remote control of the device and unauthorized firmware modification.
Affected Products:
ABB Terra AC Wallbox – <= 1.8.33
Exploit Status:
no public exploitCVE-2025-12143
CVSS 6.1A stack-based buffer overflow vulnerability in ABB Terra AC Wallbox firmware versions through 1.8.33 allows an attacker to corrupt stack memory, potentially leading to remote control of the device and unauthorized firmware modification.
Affected Products:
ABB Terra AC Wallbox – <= 1.8.33
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploitation for Client Execution
Exploit Public-Facing Application
Hijack Execution Flow
Endpoint Denial of Service
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Electric vehicle charging infrastructure vulnerabilities expose energy sector to buffer overflow attacks via Bluetooth and OCPP protocols, potentially compromising grid-connected systems.
Utilities
ABB Terra AC Wallbox buffer overflow vulnerabilities threaten utility charging networks through encrypted Bluetooth exploitation, enabling remote control and firmware manipulation attacks.
Automotive
EV charging station security flaws impact automotive ecosystem through compromised wallbox systems, affecting vehicle charging infrastructure and potential lateral movement to connected services.
Transportation
Critical infrastructure charging systems face heap and stack-based buffer overflows, threatening transportation electrification networks through OCPP protocol manipulation and Bluetooth hijacking.
Sources
- ABB Terra AC Wallboxhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-141-05Verified
- ABB Cyber Security Advisory - Terra AC Wallbox Multiple Vulnerabilitieshttps://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A8107&LanguageCode=en&DocumentPartId=&Action=LaunchVerified
- NVD - CVE-2025-10504https://nvd.nist.gov/vuln/detail/CVE-2025-10504Verified
- NVD - CVE-2025-12142https://nvd.nist.gov/vuln/detail/CVE-2025-12142Verified
- NVD - CVE-2025-12143https://nvd.nist.gov/vuln/detail/CVE-2025-12143Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial exploitation, it could likely limit the attacker's ability to escalate privileges or move laterally within the network.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to leverage elevated privileges to access other network segments or sensitive resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely limit the attacker's ability to move laterally by enforcing strict access controls between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely limit the attacker's ability to establish and maintain command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the attacker's ability to exfiltrate data by enforcing strict egress policies and monitoring outbound traffic.
While Aviatrix Zero Trust CNSF may not prevent firmware manipulation, it could likely limit the attacker's ability to propagate the impact to other devices or systems.
Impact at a Glance
Affected Business Functions
- Electric Vehicle Charging Services
- Energy Management Systems
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement firmware updates to address known vulnerabilities.
- • Enforce strict access controls and authentication mechanisms for Bluetooth communication.
- • Deploy intrusion detection systems to monitor for anomalous activities.
- • Conduct regular security assessments and penetration testing.
- • Educate users on recognizing and reporting suspicious activities.



