Impact
The EVbee DC-80 network device hosts a diagnosis web endpoint on port 8090 that accepts parameters without proper validation, allowing an attacker to inject arbitrary shell commands. This flaw enables the execution of any OS command with the privileges of the web server process, effectively granting full control over the device. The weakness is classified as CWE-77.
Affected Systems
The vulnerability affects EVbee DC-80, with no specific version details provided. Any deployment that exposes the web interface to internal or external users is at risk.
Risk and Exploitability
The CVSS score of 9.3 signals critical severity, yet the EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not yet documented in CISA’s KEV catalog. The likely attack vector is an attacker sending crafted HTTP requests to the diagnosis endpoint on port 8090, which can trigger the injection and lead to system-wide compromise if executed.
OpenCVE Enrichment