Executive brief
The Besen BS20 EV Charging Station is a home electric vehicle charger. A vulnerability in its Bluetooth Low Energy (BLE) handler allows attackers within physical proximity to potentially gain unauthorized access to the device. This is due to the use of weak, 6-digit numeric passwords and a lack of protection against offline password cracking, which could allow an attacker to take control of the charging station's settings.
Technical details
The Besen BS20 EV Charging Station (up to version 20260426) contains a weak authentication mechanism in its Bluetooth Low Energy (BLE) Handler. The device enforces a fixed 6-digit numeric password format, which limits the entropy to 1,000,000 combinations. Furthermore, the BLE authentication handshake can be captured by an attacker within radio range and subjected to offline brute-force cracking. Successful exploitation allows an attacker to recover credentials and gain unauthorized control over the device. The attack is considered high complexity as it requires capturing specific wireless traffic and performing offline analysis. As of April 2026, the vendor has acknowledged the report and is reviewing the findings.
Affected products
- Besen BS20 EV Charging Station up to 20260426
Timeline
- 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged.
- 2026-05-24: advisory: Initial disclosure via VulDB and NVD.