Impact
The fault is that the charging station lacks authentication for Bluetooth commands, allowing an unauthorized device to invoke hidden functions. Commands can leak sensitive information, force device reboots, or instruct the station to download and install a firmware image from an arbitrary URL. This broken authentication weakness (CWE‑287) gives an attacker full remote control, potentially leading to data theft, denial of service, or delivery of malicious firmware.
Affected Systems
The issue affects EVbee DC‑80 charging stations. Any unit that exposes the Bluetooth interface without requiring authentication is potentially vulnerable. No specific firmware or hardware revisions are mentioned as being limited, so the risk applies to all DC‑80 models that have a Bluetooth command channel.
Risk and Exploitability
The high severity CVSS score of 8.7 indicates a serious risk, but the EPSS score of less than 1% shows that exploitation is currently unlikely. The vulnerability is not yet listed in CISA KEV. The likely attack vector is proximity‑based Bluetooth communication; a malicious device within range can send crafted commands to the charging station to perform the exposed actions.
OpenCVE Enrichment