Impact
The vulnerability arises from a lack of cryptographic signature validation in the firmware update process, allowing an attacker with any ability to trigger a firmware upload to submit malicious files that are then executed by the device. This flaw completely undermines firmware integrity and permits full remote code execution, giving an attacker potential control over the system, including the ability to exfiltrate data, disrupt operations, or repurpose the device for further attacks.
Affected Systems
The flaw impacts EVbee DC‑80 devices. No specific model or firmware version details are disclosed in the current data.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1% points to a low current exploitation probability, possibly due to limited exposure. The device most likely uses a network‑based update interface, so a remote attacker who can reach that interface—either directly or via a compromised management account—could upload a crafted firmware image. Because no signature checks are performed, the malicious payload would be accepted and executed, enabling remote code execution.
OpenCVE Enrichment