Description
Various sensitive information such as passwords and charging card UIDs are written to log files.
Published: 2026-07-13
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Sensitive data such as passwords and charging card UIDs are written to log files on EVbee DC-80 devices. This flaw can allow an attacker or an insider with access to the logs to read confidential information, compromising confidentiality and potentially enabling further attacks. The vulnerability is classified under CWE-532 and carries a CVSS score of 9.2, indicating a high severity impact.

Affected Systems

EVbee DC-80 devices are affected. No specific product version details are provided in the available data.

Risk and Exploitability

The CVSS score indicates a severe risk, while the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an adversary who can read the log files, either by direct access to the device or through network access to the logging platform. Once the logs are accessed, the attacker can exfiltrate sensitive credentials and card identifiers for later use.

Generated by OpenCVE AI on July 31, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware or patch update for the EVbee DC-80 that removes sensitive data from logs
  • Configure the device’s logging settings to exclude passwords and sensitive identifiers from log entries
  • Encrypt log files and enforce strict access controls to limit read permissions to authorized personnel
  • Rotate and securely delete logs regularly to reduce the window of opportunity for data exposure

Generated by OpenCVE AI on July 31, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Evbee
Evbee dc-80
Vendors & Products Evbee
Evbee dc-80

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Various sensitive information such as passwords and charging card UIDs are written to log files.
Title Sensitive information is written to logs
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published:

Updated: 2026-07-16T15:41:04.833Z

Reserved: 2026-01-06T11:08:58.183Z

Link: CVE-2026-22098

cve-icon Vulnrichment

Updated: 2026-07-13T14:21:13.793Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File