Junglewise Threat Intelligence

CVE-2026-22095: EVbee DC-80 command injection in network diagnosis endpoint

CVE-2026-22095 · Severity: info · CVSS 9.3 · Published 2026-07-13

Technologies: EVbee DC-80. Vendors: EVbee.

Executive brief

A security vulnerability has been identified in EVbee DC-80 electric vehicle charging stations. The device's network diagnostic tool, accessible via a web interface, contains a flaw that allows unauthorized individuals to take full control of the station over the network. This could lead to service disruptions, unauthorized access to the device's settings, or use of the station as a foothold to attack other parts of the local network.

Technical details

A command injection vulnerability (CWE-77) exists in the network diagnosis endpoint of the EVbee DC-80 web server, which listens on port 8090. The flaw stems from improper neutralization of special elements in user-supplied input used to construct system commands. An unauthenticated remote attacker can exploit this by sending specially crafted requests to the endpoint, leading to arbitrary command execution with the privileges of the web server. This vulnerability affects versions prior to 1.5.1. A patch is available in version 1.5.1.

Affected products

  • EVbee DC-80 versions before 1.5.1

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References

Related threats