Executive brief
A security flaw in EVbee DC-80 electric vehicle charging stations allows unauthorized individuals within Bluetooth range to control the device. An attacker could force the station to reboot, steal sensitive information, or redirect the device to install malicious software updates. This could lead to service disruptions for customers and potential long-term compromise of the charging infrastructure.
Technical details
The EVbee DC-80 charging station suffers from improper authentication (CWE-287) in its Bluetooth communication interface. An attacker within physical proximity (Bluetooth range) can issue commands without providing credentials. This exposed functionality allows for sensitive information leakage, the ability to trigger device reboots (denial of service), and the capability to push a rogue firmware update URL to the device. The vulnerability is addressed in version 1.5.4.
Affected products
- EVbee DC-80 versions before 1.5.4
Timeline
- 2026-07-13: advisory: CVE-2026-22099 published by NVD and DIVD