Impact
Sensitive data such as passwords and charging card UIDs are written to log files on EVbee DC-80 devices. This flaw can allow an attacker or an insider with access to the logs to read confidential information, compromising confidentiality and potentially enabling further attacks. The vulnerability is classified under CWE-532 and carries a CVSS score of 9.2, indicating a high severity impact.
Affected Systems
EVbee DC-80 devices are affected. No specific product version details are provided in the available data.
Risk and Exploitability
The CVSS score indicates a severe risk, while the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an adversary who can read the log files, either by direct access to the device or through network access to the logging platform. Once the logs are accessed, the attacker can exfiltrate sensitive credentials and card identifiers for later use.
OpenCVE Enrichment