Junglewise Threat Intelligence

CVE-2026-9394: Besen BS20 EV Charging Station weak authentication in BLE handler

CVE-2026-9394 · Severity: low · CVSS 3.1 · Published 2026-05-24

Technologies: Besen BS20 EV Charging Station. Vendors: Besen.

Executive brief

The Besen BS20 EV Charging Station is a home electric vehicle charger. A vulnerability in its Bluetooth Low Energy (BLE) handler allows attackers within physical proximity to potentially gain unauthorized access to the device. This is due to the use of weak, 6-digit numeric passwords and a lack of protection against offline password cracking, which could allow an attacker to take control of the charging station's settings.

Technical details

The Besen BS20 EV Charging Station (up to version 20260426) contains a weak authentication mechanism in its Bluetooth Low Energy (BLE) Handler. The device enforces a fixed 6-digit numeric password format, which limits the entropy to 1,000,000 combinations. Furthermore, the BLE authentication handshake can be captured by an attacker within radio range and subjected to offline brute-force cracking. Successful exploitation allows an attacker to recover credentials and gain unauthorized control over the device. The attack is considered high complexity as it requires capturing specific wireless traffic and performing offline analysis. As of April 2026, the vendor has acknowledged the report and is reviewing the findings.

Affected products

  • Besen BS20 EV Charging Station up to 20260426

Timeline

  • 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged.
  • 2026-05-24: advisory: Initial disclosure via VulDB and NVD.

References

Related threats