Impact
The ReserveLogin function of the OCPP DataTransfer message can be abused to inject arbitrary operating‑system commands. When the data field of a ReserveLogin request is manipulated, the flaw, formally described as CWE‑78, allows an attacker to fully compromise the charging station, jeopardizing confidentiality, integrity, and availability.
Affected Systems
The fault affects EVbee DC‑80 charging stations that implement the OCPP ReserveLogin DataTransfer as listed by the CNA, so all DC‑80 devices that expose this message are potentially impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity level and the EPSS score of <1% indicates a very low, yet nonzero, exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attacker must be able to send a crafted ReserveLogin request, likely by having access to the OCPP network segment or possessing a client capable of communicating with the charging station. Once the message is accepted, the injected commands execute with root privileges, granting full control over the device.
OpenCVE Enrichment