Junglewise Threat Intelligence

CVE-2026-22097: EVbee DC-80 missing signature validation in firmware update

CVE-2026-22097 · Severity: info · CVSS 9.3 · Published 2026-07-13

Technologies: EVbee DC-80. Vendors: EVbee.

Executive brief

A critical security flaw has been identified in EVbee DC-80 electric vehicle charging stations. The device's update system fails to verify the authenticity of new software, allowing an attacker to install malicious firmware. If exploited, this could allow a remote attacker to take complete control of the charging station, potentially leading to service disruption, data theft, or further network intrusion.

Technical details

The EVbee DC-80 firmware update mechanism lacks cryptographic signature validation (CWE-347). An attacker with network access to the firmware update interface can upload and install a modified or entirely malicious firmware image. Because the system does not verify the origin or integrity of the update, the malicious file is executed with high privileges. This leads to full system compromise and arbitrary code execution. The vulnerability is addressed in version 1.5.1.

Affected products

  • EVbee DC-80 versions before 1.5.1

Timeline

  • 2026-07-13: advisory: CVE published by NVD and DIVD

References

Related threats