The Containment Era is here. →Explore

Executive Summary

In September 2025, ABB identified multiple buffer overflow vulnerabilities in its Terra AC Wallbox electric vehicle chargers, specifically affecting firmware versions up to 1.8.33. These vulnerabilities, cataloged as CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143, could allow attackers with adjacent network access and high privileges to execute arbitrary code, potentially leading to unauthorized control over the device. ABB promptly released firmware version 1.8.36 to address these issues and recommended immediate updates to mitigate potential risks.

The discovery of these vulnerabilities underscores the critical importance of securing IoT devices, especially those connected to critical infrastructure like energy distribution. As the adoption of electric vehicle chargers grows, ensuring robust cybersecurity measures is essential to prevent potential exploitation that could disrupt services and compromise user safety.

Why This Matters Now

The increasing integration of IoT devices in critical infrastructure highlights the urgent need for proactive cybersecurity measures to prevent potential exploits that could disrupt essential services and compromise user safety.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerabilities include CVE-2025-10504 (heap-based buffer overflow), CVE-2025-12142 (buffer copy without checking size of input), and CVE-2025-12143 (stack-based buffer overflow), all affecting firmware versions up to 1.8.33.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial exploitation, it could likely limit the attacker's ability to escalate privileges or move laterally within the network.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to leverage elevated privileges to access other network segments or sensitive resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security could likely limit the attacker's ability to move laterally by enforcing strict access controls between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control could likely limit the attacker's ability to establish and maintain command and control channels by monitoring and controlling outbound communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the attacker's ability to exfiltrate data by enforcing strict egress policies and monitoring outbound traffic.

Impact (Mitigations)

While Aviatrix Zero Trust CNSF may not prevent firmware manipulation, it could likely limit the attacker's ability to propagate the impact to other devices or systems.

Impact at a Glance

Affected Business Functions

  • Electric Vehicle Charging Services
  • Energy Management Systems
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

n/a

Recommended Actions

  • Implement firmware updates to address known vulnerabilities.
  • Enforce strict access controls and authentication mechanisms for Bluetooth communication.
  • Deploy intrusion detection systems to monitor for anomalous activities.
  • Conduct regular security assessments and penetration testing.
  • Educate users on recognizing and reporting suspicious activities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image