Impact
The EVbee Service Android application fails to validate the TLS server certificate and uses weak RC4 encryption with a hard‑coded key. This configuration allows an attacker positioned on the network path between the app and the EVbee server to intercept, read, and modify all traffic. The traffic contains access codes for charging stations, so interception can expose these codes and potentially enable unauthorized use of the stations.
Affected Systems
EVbee Service application for Android, version 1.4.101.00.
Risk and Exploitability
The CVSS score of 9.5 indicates a Critical severity flaw, while the EPSS score of less than 1 % suggests that exploitation opportunities are currently low. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly observed exploit packages. Because the app does not validate server certificates, an attacker can perform a Man‑in‑the‑Middle on any network path to the EVbee server. Weak RC4 encryption with a hard‑coded key allows the attacker to decrypt and alter the communication without requiring any privileged device access or additional credentials.
OpenCVE Enrichment