Executive brief
The EVbee Service Android app, used for managing electric vehicle charging stations, fails to properly verify the identity of the servers it communicates with. This flaw allows an attacker to intercept and modify data sent between the app and the server, potentially gaining access to sensitive charging station access codes. Such an exploit could lead to unauthorized use of charging infrastructure or the theft of operational credentials.
Technical details
The EVbee Service Android app (v1.4.101.00) is vulnerable to a Man-in-the-Middle (MitM) attack due to improper certificate validation (CWE-295). While the app uses HTTPS, it does not validate the server-provided certificate, allowing an attacker on the network path to intercept traffic. Furthermore, the application employs a secondary layer of weak encryption using the RC4 algorithm with a hardcoded key. An attacker can exploit these weaknesses to decrypt, view, and modify sensitive data in transit, specifically charging station access codes. The vulnerability is exploitable by any network-adjacent or remote attacker capable of intercepting the app's traffic.
Affected products
- EVbee EVbee Service v1.4.101.00 and earlier
Timeline
- 2026-07-13: advisory: CVE-2026-22093 published by DIVD and NVD