Executive brief
A critical security flaw has been identified in EVbee DC-80 electric vehicle charging stations where the administrative web interface on port 8090 does not require a password. This allows any unauthorized person with network access to the device to view sensitive information, including configured passwords, and upload potentially malicious files. An exploit could lead to full device compromise, unauthorized access to the charging network, and disruption of service.
Technical details
The EVbee DC-80 charging station suffers from a missing authentication vulnerability (CWE-306) on its web management interface listening on TCP port 8090. A remote, unauthenticated attacker can access the webserver to leak sensitive configuration data, including plaintext passwords, and interact with various endpoints to upload files. This vulnerability provides a direct path for full system compromise and persistent access. The issue is addressed in firmware version 1.5.1.
Affected products
- EVbee DC-80 versions before 1.5.1
Timeline
- 2026-07-13: advisory: NVD publication date
- 2026-07-13: disclosed: DIVD advisory published