Description
A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipulation can lead to weak password requirements. The attack needs to be done within the local network. This attack is characterized by high complexity. The exploitability is said to be difficult. The original disclosure mentions, that "[t]hese vulnerabilities have been reported to Besen and we have received their acknowlegement that they are reviewing this as of April 2026."
Published: 2026-05-24
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an attacker on the local network to exploit a weak password requirement in the Bluetooth Low Energy handler of the Besen BS20 EV Charging Station. By manipulating the BLE interface it becomes possible to authenticate without the strong credentials normally expected, allowing the attacker to control charging operations or gain access to device state information. This weakness arises from inadequate authentication (CWE‑521) and could lead to unauthorized configuration changes or misuse of the charging session, compromising the confidentiality and integrity of the charging process.

Affected Systems

Besen BS20 EV Charging Station, firmware versions released through 2026‑04‑26 are affected. No specific model or version sub‑range beyond the upstream release date is detailed.

Risk and Exploitability

The CVSS base score of 2.3 indicates low systemic impact under the current conditions; however, the attack requires physical proximity within the local network and has a high complexity and difficult exploitability rating. Because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the probability of widespread exploitation is considered low but the local nature of the attack means that any compromised network segment could be used to enumerate or manipulate the charging station. There is no currently available public exploit, but the weakness is exploitable if the attacker can induce the device to perform a BLE interaction, thus significant risk remains for local network owners.

Generated by OpenCVE AI on May 24, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released firmware upgrade that addresses the weak password issue.
  • Disable or block the BLE service on the charging station to prevent local network access if a patch is not yet available.
  • Segregate the charging station into a separate network segment or VLAN, restricting BLE communications to trusted devices only.
  • Enforce a strong password or authentication policy for BLE if the device supports configuration changes.
  • Monitor BLE traffic and station logs for suspicious authentication attempts.

Generated by OpenCVE AI on May 24, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 24 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipulation can lead to weak password requirements. The attack needs to be done within the local network. This attack is characterized by high complexity. The exploitability is said to be difficult. The original disclosure mentions, that "[t]hese vulnerabilities have been reported to Besen and we have received their acknowlegement that they are reviewing this as of April 2026."
Title Besen BS20 EV Charging Station Bluetooth Low Energy weak password
First Time appeared Besen
Besen bs20 Ev Charging Station
Weaknesses CWE-521
CPEs cpe:2.3:a:besen:bs20_ev_charging_station:*:*:*:*:*:*:*:*
Vendors & Products Besen
Besen bs20 Ev Charging Station
References
Metrics cvssV2_0

{'score': 1.8, 'vector': 'AV:A/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Besen Bs20 Ev Charging Station
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-24T19:30:11.000Z

Reserved: 2026-05-24T06:18:52.619Z

Link: CVE-2026-9394

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-24T20:30:07Z

Weaknesses