A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
Conclusion & alert: CVE-2021-22707 is rated High Risk (78/100): CVSS Critical severity, with high exploitation likelihood (EPSS 91.57%, 100th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +3.88% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 87.69% | 91.57% | +3.88% |
| 2 | 2025-11-18 | 91.57% | 87.69% | -3.88% |
| 3 | 2025-10-09 | — | 91.57% | — |
Full EPSS history (31 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| schneider-electric | evlink_city_evc1s22p4_firmware | < r8_v3.4.0.1 | cpe:2.3:o:schneider-electric:evlink_city_evc1s22p4_firmware:*:*:*:*:*:*:*:* |
| schneider-electric | evlink_city_evc1s7p4_firmware | < r8_v3.4.0.1 | cpe:2.3:o:schneider-electric:evlink_city_evc1s7p4_firmware:*:*:*:*:*:*:*:* |
| schneider-electric | evlink_parking_evw2_firmware | < r8_v3.4.0.1 | cpe:2.3:o:schneider-electric:evlink_parking_evw2_firmware:*:*:*:*:*:*:*:* |
| schneider-electric | evlink_parking_evf2_firmware | < r8_v3.4.0.1 | cpe:2.3:o:schneider-electric:evlink_parking_evf2_firmware:*:*:*:*:*:*:*:* |
| schneider-electric | evlink_parking_ev.2_firmware | < r8_v3.4.0.1 | cpe:2.3:o:schneider-electric:evlink_parking_ev.2_firmware:*:*:*:*:*:*:*:* |
| schneider-electric | evlink_smart_wallbox_evb1a_firmware | < r8_v3.4.0.1 | cpe:2.3:o:schneider-electric:evlink_smart_wallbox_evb1a_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06 | Vendor Advisory |