Executive brief
The Besen BS20 EV Charging Station is a home electric vehicle charger. A security flaw allows user credentials to be transmitted in plain text over the local network and Bluetooth. An attacker on the same network could intercept these credentials to gain unauthorized control over the charging station, potentially disrupting vehicle charging or modifying device settings.
Technical details
The Besen BS20 EV Charging Station (up to version 20260426) suffers from a cleartext transmission of sensitive information vulnerability (CWE-522). User credentials, including old and new passwords during change operations, are transmitted in plaintext over Bluetooth Low Energy (BLE) and UDP. Additionally, the device frequently broadcasts these passwords via UDP packets. An attacker positioned within the local network or within BLE range can capture these packets to recover credentials. This allows for unauthorized access and control of the device. As of April 2026, the vendor has acknowledged the report and is reviewing the issue.
Affected products
- Besen BS20 EV Charging Station up to 20260426
Timeline
- 2026-04-26: disclosed: Vulnerability reported to vendor and acknowledged
- 2026-05-24: advisory: NVD/VulDB advisory published