Junglewise Threat Intelligence

CVE-2026-22098: Unknown EV Charging Station sensitive information exposure in log files

CVE-2026-22098 · Severity: info · Published 2026-07-13

Vendors: Unknown.

Executive brief

A vulnerability exists where electric vehicle charging station software records sensitive information, including user passwords and charging card identification numbers, into plain-text log files. If an unauthorized person gains access to these logs, they could steal user credentials or clone charging cards to obtain free services. This poses a significant risk to customer privacy and could lead to financial fraud or unauthorized access to user accounts.

Technical details

The vulnerability is classified as an Information Exposure through Log Files (CWE-532). The affected software fails to sanitize or mask sensitive data before writing to system logs, resulting in the storage of cleartext passwords and charging card UIDs. An attacker with local access to the file system or administrative access to the logging interface could retrieve these credentials. This exposure facilitates credential stuffing, account takeover, and unauthorized use of charging services. Users are advised to restrict log access and apply any available firmware updates that implement proper data masking.

Affected products

  • Unknown EV Charging Station Software

Timeline

  • 2026-07-13: advisory: Initial disclosure by NVD and DIVD CSIRT.

References