CVE-2026-33009 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 switch_three_phases_while_charging race condition (GHSA-33qh-fg6f-jjx5 / EUVD-2026-16250)
A vulnerability labeled as critical has been found in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0. The affected element is an unknown function of the file /everest_external/nodered/{connector}/cmd/switch_three_phases_while_charging. Such manipulation leads to race condition.
This vulnerability is listed as CVE-2026-33009. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.