Description
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.
Published: 2026-07-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The fault is that the charging station lacks authentication for Bluetooth commands, allowing an unauthorized device to invoke hidden functions. Commands can leak sensitive information, force device reboots, or instruct the station to download and install a firmware image from an arbitrary URL. This broken authentication weakness (CWE‑287) gives an attacker full remote control, potentially leading to data theft, denial of service, or delivery of malicious firmware.

Affected Systems

The issue affects EVbee DC‑80 charging stations. Any unit that exposes the Bluetooth interface without requiring authentication is potentially vulnerable. No specific firmware or hardware revisions are mentioned as being limited, so the risk applies to all DC‑80 models that have a Bluetooth command channel.

Risk and Exploitability

The high severity CVSS score of 8.7 indicates a serious risk, but the EPSS score of less than 1% shows that exploitation is currently unlikely. The vulnerability is not yet listed in CISA KEV. The likely attack vector is proximity‑based Bluetooth communication; a malicious device within range can send crafted commands to the charging station to perform the exposed actions.

Generated by OpenCVE AI on July 31, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest EVbee firmware update that implements authentication for Bluetooth commands
  • Disable the charging station’s Bluetooth interface or block unauthorized Bluetooth traffic using a local firewall or access control list
  • Isolate the device on a dedicated network segment and monitor for unexpected Bluetooth activity

Generated by OpenCVE AI on July 31, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Evbee
Evbee dc-80
Vendors & Products Evbee
Evbee dc-80

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.
Title Missing authentication for Bluetooth communication
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published:

Updated: 2026-07-16T15:41:07.703Z

Reserved: 2026-01-06T11:08:58.183Z

Link: CVE-2026-22099

cve-icon Vulnrichment

Updated: 2026-07-13T14:22:45.467Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses