An attacker who successfully exploited this remotely exploitable vulnerability, discovered by Itai Shmueli of Saiflow, could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.
Terra AC wallbox is a Level 2 Electric Vehicle charger.
- Terra AC wallbox (UL40/80A) up to and including version 1.8.32
- Terra AC wallbox (UL32A) up to and including version 1.8.2
- Terra AC wallbox (MID/ CE) up to and including version 1.8.32
- Terra AC wallbox (JP) up to and including version 1.8.2
In the vulnerability, there is potential risk to pollute the memory when a specially crafted OCPP message ends up sent to a target vulnerable charger by exploiting unencrypted communication to the Charging Station Management System (CSMS) or fully remotely from its CSMS server.
To attack with this kind of message, hackers must hijack CSMS (OCPP backends) first and then can send messages, or the way to OCPP backend is unsafe itself which can cause any kind of attack behavior.
CVE-2025-5517 is the case number for the vulnerability, which has a CVSS V3 base score of 6.8.
Industrial Sectors
The product sees use in the commercial facilities, critical manufacturing, energy, and transportation systems sectors, and on a global basis.
In terms of mitigations, ABB fixed the problem in the following product versions:
- Terra AC wallbox (UL40/80A) version 1.8.33
- Terra AC wallbox (UL32A) version 1.8.34
- Terra AC MID version 1.8.34
- Terra AC Juno CE version 1.8.34
- Terra AC PTB version 1.8.33
- Terra AC wallbox (JP) version 1.8.34
Additionally, ABB recommends not using unsafe mode (http) to connect your charger to your backend. It could end up attacked by malicious person or organization as a common knowledge. ABB recommends customers apply the update at earliest convenience.
In terms of workarounds, make sure OCPP backend that chargers connect to end up strictly secured to avoid any kind of attack especially the communication relevant components. Use https (TLS) as basic communication foundation between charger and OCPP backend instead of http.
The vulnerability ends up caused by firmware which it didn’t limit the length of OCPP field in certain case.
Meanwhile, an attacker who successfully exploited this vulnerability could cause the affected system node to take control of the charger to response wrong messages, cause denial-of-service, compromise internal state, and possibly remote code execution.
An attacker could try to exploit the vulnerability by sending a specially crafted OCPP message to chargers via OCPP backend(CSMS), which could be done remotely. This would require the attacker has access to the system network and hijack the API of sending message or hijack the network data directly if the charger ends up connected with unsafe http mode.
ABB has not received any information indicating this vulnerability is undergoing active exploitation.

