Junglewise Threat Intelligence

CVE-2026-22100: EVbee DC-80 command injection in OCPP ReserveLogin

CVE-2026-22100 · Severity: info · CVSS 8.6 · Published 2026-07-13

Technologies: EVbee DC-80. Vendors: EVbee.

Executive brief

A security vulnerability has been identified in EVbee DC-80 electric vehicle charging stations. The issue exists in how the station processes specific management messages used for communication between the charger and its central management system. If exploited, an attacker could gain full administrative control over the charging station, potentially leading to service disruption, unauthorized access to the device's operating system, or further network compromise.

Technical details

A command injection vulnerability (CWE-78) exists in the EVbee DC-80 charging station firmware prior to version 1.5.1. The flaw is located within the handling of the Open Charge Point Protocol (OCPP) DataTransfer message 'ReserveLogin'. By supplying maliciously crafted data values within this message, an attacker with high privileges can bypass input sanitization to execute arbitrary operating system commands with root privileges. The attack is network-reachable, though it requires high privileges (PR:H) typically associated with the central management system or an administrative user. A fix is available in version 1.5.1.

Affected products

  • EVbee DC-80 versions before 1.5.1

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: disclosed

References

Related threats