Service shutdown via leaked ISO 15118 sockets
Published Jan 21, 2026 · Updated Jan 21, 2026
Resource exhaustion in EVerest Core before 2025.10.0 allows remote attackers to shut down charging-station services via SDP requests. TbdController::handle_sdp_server_input replaces its Session without unregistering the prior IConnection file descriptor and callback from PollManager, leaving a bound TCP socket and dangling callback after each valid request. An unauthenticated attacker on the IPv6 link can repeat valid SDP multicast requests to exhaust file descriptors or invoke stale callback state, crashing the module and terminating every EVerest process.
Summary
What happened
Resource exhaustion in EVerest Core before 2025.10.0 allows remote attackers to shut down charging-station services via SDP requests. TbdController::handle_sdp_server_input replaces its Session without unregistering the prior IConnection file descriptor and callback from PollManager, leaving a bound TCP socket and dangling callback after each valid request. An unauthenticated attacker on the IPv6 link can repeat valid SDP multicast requests to exhaust file descriptors or invoke stale callback state, crashing the module and terminating every EVerest process.
The record
- CVE
- CVE-2025-68136
- Published
- Jan 21, 2026
- Updated
- Jan 21, 2026
- Vendor
- EVerest
- Product
- EVerest Core
- Classifications
- CWE-770, T1499
- Attack vector
- adjacent
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jan 21, 2026CVE publishedPublication date reported by the CVE source.
- Jan 21, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 2025.10.0
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Vendor SDP request proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo