CVE-2025-68135
CVE-2025-68135 is a medium-severity vulnerability in Linuxfoundation Everest with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-703.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-206322
- Weakness: CWE-703
- Affected product: Linuxfoundation Everest
- Published:
- Last modified:
Description
EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by the `TbdController` loop, leading to its caller and itself to silently terminates. Thus, this leads to a denial of service as it is responsible of SDP and ISO15118-20 servers. Version 2025.10.0 fixes the issue.
Frequently asked questions
- What is CVE-2025-68135?
- EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by the `TbdController` loop, leading to its caller and itself to silently terminates. Thus, this leads to a denial of service as it is responsible of SDP and ISO15118-20 servers. Version 2025.10.0 fixes the issue.
- How severe is CVE-2025-68135?
- CVE-2025-68135 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2025-68135 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-68135?
- CVE-2025-68135 affects Linuxfoundation Everest. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-68135?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-68135 have an EU (EUVD) identifier?
- Yes. CVE-2025-68135 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-206322.
- When was CVE-2025-68135 published?
- CVE-2025-68135 was published on 2026-01-21 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:*
More vulnerabilities in Linuxfoundation Everest
- CVE-2026-27816 — Critical (CVSS 9.1): EVerest is an EV charging software stack. Prior to versions to 2026.02.0,…
- CVE-2026-27815 — Critical (CVSS 9.1): EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup…
- CVE-2026-22790 — High (CVSS 8.8): EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len`…
- CVE-2026-23995 — High (CVSS 8.4): EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface…
- CVE-2026-22593 — High (CVSS 8.4): EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate…
- CVE-2025-68137 — High (CVSS 8.3): EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in…
All CVEs affecting Linuxfoundation Everest →
Other CWE-703 vulnerabilities
- CVE-2026-20329 — Critical (CVSS 9.9): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security…
- CVE-2025-13026 — Critical (CVSS 9.8): Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in…
- CVE-2025-13023 — Critical (CVSS 9.8): Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in…
- CVE-2025-13022 — Critical (CVSS 9.8): Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and…
- CVE-2025-13021 — Critical (CVSS 9.8): Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and…
- CVE-2026-71640 — Critical (CVSS 9.1): An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows…