Description
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
Published: 2026-07-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The EVbee DC‑80’s NPC start endpoint, listening on port 8090, has a command‑injection flaw (CWE‑77) that lets an attacker execute arbitrary operating‑system commands. The vulnerability allows unauthenticated remote code execution, giving the attacker full control over the device and potentially compromising any connected systems.

Affected Systems

EVbee DC‑80 devices are affected. No specific firmware or version range is listed; the NPC start endpoint on port 8090, regardless of firmware version.

Risk and Exploitability

The CVSS score of 9.3 reflects a severe impact and low attack difficulty. The EPSS score of < 1% indicates that exploitation is unlikely but not negligible. The vulnerability has not appeared in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw via unauthenticated requests to the NPC start endpoint on port 8090, enabling the execution of arbitrary operating‑system commands, which could allow full control over the device.

Generated by OpenCVE AI on July 31, 2026 at 11:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑published firmware or software patch that addresses the command injection flaw.
  • Configure a firewall to block or restrict access to TCP port 8090 from untrusted networks.
  • Restrict the device’s exposure by deploying it behind a VPN or segmenting it on an isolated network.

Generated by OpenCVE AI on July 31, 2026 at 11:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Evbee
Evbee dc-80
Vendors & Products Evbee
Evbee dc-80

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
Title Command injection in NPC start web endpoint
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published:

Updated: 2026-07-16T15:41:13.345Z

Reserved: 2026-01-06T11:08:58.184Z

Link: CVE-2026-22103

cve-icon Vulnrichment

Updated: 2026-07-13T14:15:22.817Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')