Impact
The webserver who can reach the endpoint can read passwords—and upload files. This can expose confidential information and potentially allow modification of system files. The weakness is identified as CWE‑306, an authentication failure that permits unauthorized access.
Affected Systems
The vulnerability affects the EVbee DC‑80 product. No specific firmware or software version is listed, so all installations running the webserver component that listens on port 8090 are potentially affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity, reflecting the potential for remote attackers to exfiltrate sensitive data or alter system state. The EPSS score of less than 1% shows that exploitation is currently uncommon, but the flaw remains highly desirable for attackers. The issue is not listed in the CISA KEV catalog, and the likely attack vector is a network‑based HTTP request to the unprotected port 8090.
OpenCVE Enrichment