Executive brief
The Besen BS20 electric vehicle charging station contains a security flaw in how it handles wireless software updates. An attacker could potentially trick the station into installing malicious software by impersonating the update server. If successful, this could allow an attacker to take full control of the charger, potentially damaging the device or manipulating charging behavior.
Technical details
The Besen BS20 EV Charging Station's OTA Update Installation Handler fails to properly validate the authenticity and integrity of firmware updates. While some validation checks exist, they are insufficient to prevent an attacker from spoofing the update server and delivering malicious firmware. The attack is carried out remotely over the network but requires a high degree of complexity to successfully bypass existing safeguards. Successful exploitation allows for full device compromise and the ability to manipulate charging parameters. As of the disclosure, the vendor was reviewing the findings.
Affected products
- Besen BS20 EV Charging Station up to 20260426
Timeline
- 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged for review.
- 2026-05-24: advisory: Public disclosure of the vulnerability.