Junglewise Threat Intelligence

CVE-2026-9396: Besen BS20 EV Charging Station UI spoofing in Firmware Version Check

CVE-2026-9396 · Severity: low · CVSS 3.7 · Published 2026-05-24

Technologies: Besen BS20 EV Charging Station. Vendors: Besen.

Executive brief

The Besen BS20 EV Charging Station is a home electric vehicle charger. A security flaw in its firmware update process allows an attacker to trick the mobile app into displaying fake update notifications or incorrect version information. While this does not directly compromise the charger's hardware, it can be used to mislead users or facilitate further social engineering attacks.

Technical details

The Besen BS20 EV Charging Station (up to version 20260426) is vulnerable to improper restriction of rendered UI layers (CWE-1021) within its firmware version check functionality. The mobile application does not validate the integrity or authenticity of firmware version responses received during update checks. A remote attacker can intercept and modify these responses to display an arbitrary 'newer' version, enabling the upgrade button even when the device is current. This allows for UI spoofing and the presentation of misleading update prompts to the user. The attack requires high complexity as it typically involves a man-in-the-middle (MitM) position to intercept the network traffic.

Affected products

  • Besen BS20 EV Charging Station up to 20260426

Timeline

  • 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged.
  • 2026-05-24: advisory: NVD/VulDB advisory published.

References

Related threats