Executive brief
A critical security vulnerability has been identified in EVbee DC-80 electric vehicle charging stations. An attacker can remotely take control of the device by sending malicious commands to its internal web server. This could allow unauthorized parties to disrupt charging services, manipulate device settings, or gain a foothold in the local network.
Technical details
A command injection vulnerability exists in the EVbee DC-80 charging station's web server, specifically within the 'NPC start' endpoint listening on port 8090. The flaw is caused by improper neutralization of special elements used in a command (CWE-77). An unauthenticated remote attacker can exploit this by sending specially crafted requests to the affected endpoint, leading to arbitrary command execution with high privileges. The vulnerability affects versions prior to 1.5.1 and has been assigned a CVSS 4.0 base score of 9.3.
Affected products
- EVbee DC-80 versions before 1.5.1
Timeline
- 2026-07-13: advisory: NVD published the CVE record based on DIVD disclosure.
- 2026-07-13: disclosed: Vulnerability disclosed by the Dutch Institute for Vulnerability Disclosure (DIVD).