Security Advisory

CVE-2026-33015

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-26 16:42:50
Last updated 2026-03-26 17:35:07
Assigner GitHub_M
State PUBLISHED

Description

EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE can return to `PrepareCharging` via the EVs BCB toggle, allowing session restart. This breaks the irreversibility of remote stop and can bypass operational/billing/safety controls. Version 2026.02.0 contains a patch.