ChargePoint Home Flex flaw (ZDI-26-197) allows unauthenticated network-adjacent remote code execution as root via OCPP message handling
| Publisher | PCA Cyber Security |
| Report | PCA Cyber Security Global Automotive Cybersecurity Report Q1 2026 |
| Published | 1 May 2026 |
| Topics | Automotive Cybersecurity, EV Charging, ChargePoint, RCE |
Published by PCA Cyber Security in PCA Cyber Security Global Automotive Cybersecurity Report Q1 2026, 1 May 2026. The figure is taken from the report as published; the full methodology is in the source.