Junglewise Threat Intelligence

CVE-2026-9397: Besen BS20 EV Charging Station improper authorization in OTA Update Handler

CVE-2026-9397 · Severity: high · CVSS 8.1 · Published 2026-05-24

Technologies: Besen BS20 EV Charging Station. Vendors: Besen.

Executive brief

The Besen BS20 electric vehicle charging station contains a security flaw in how it handles wireless software updates. An attacker could potentially trick the station into installing malicious software by impersonating the update server. If successful, this could allow an attacker to take full control of the charger, potentially damaging the device or manipulating charging behavior.

Technical details

The Besen BS20 EV Charging Station's OTA Update Installation Handler fails to properly validate the authenticity and integrity of firmware updates. While some validation checks exist, they are insufficient to prevent an attacker from spoofing the update server and delivering malicious firmware. The attack is carried out remotely over the network but requires a high degree of complexity to successfully bypass existing safeguards. Successful exploitation allows for full device compromise and the ability to manipulate charging parameters. As of the disclosure, the vendor was reviewing the findings.

Affected products

  • Besen BS20 EV Charging Station up to 20260426

Timeline

  • 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged for review.
  • 2026-05-24: advisory: Public disclosure of the vulnerability.

References

Related threats