Junglewise Threat Intelligence

CVE-2026-22099: EVbee DC-80 improper authentication in Bluetooth interface

CVE-2026-22099 · Severity: info · CVSS 8.7 · Published 2026-07-13

Technologies: EVbee DC-80. Vendors: EVbee.

Executive brief

A security flaw in EVbee DC-80 electric vehicle charging stations allows unauthorized individuals within Bluetooth range to control the device. An attacker could force the station to reboot, steal sensitive information, or redirect the device to install malicious software updates. This could lead to service disruptions for customers and potential long-term compromise of the charging infrastructure.

Technical details

The EVbee DC-80 charging station suffers from improper authentication (CWE-287) in its Bluetooth communication interface. An attacker within physical proximity (Bluetooth range) can issue commands without providing credentials. This exposed functionality allows for sensitive information leakage, the ability to trigger device reboots (denial of service), and the capability to push a rogue firmware update URL to the device. The vulnerability is addressed in version 1.5.4.

Affected products

  • EVbee DC-80 versions before 1.5.4

Timeline

  • 2026-07-13: advisory: CVE-2026-22099 published by NVD and DIVD

References

Related threats