Impact
The EVbee DC‑80’s NPC start endpoint, listening on port 8090, has a command‑injection flaw (CWE‑77) that lets an attacker execute arbitrary operating‑system commands. The vulnerability allows unauthenticated remote code execution, giving the attacker full control over the device and potentially compromising any connected systems.
Affected Systems
EVbee DC‑80 devices are affected. No specific firmware or version range is listed; the NPC start endpoint on port 8090, regardless of firmware version.
Risk and Exploitability
The CVSS score of 9.3 reflects a severe impact and low attack difficulty. The EPSS score of < 1% indicates that exploitation is unlikely but not negligible. The vulnerability has not appeared in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw via unauthenticated requests to the NPC start endpoint on port 8090, enabling the execution of arbitrary operating‑system commands, which could allow full control over the device.
OpenCVE Enrichment