Executive brief
The Besen BS20 EV Charging Station is a home electric vehicle charger. A security flaw in its communication protocols allows an attacker on the same local network to intercept and replay commands. This could allow an unauthorized person to tamper with charging settings, such as starting or stopping a charge or changing the power levels.
Technical details
The Besen BS20 EV Charging Station (up to version 20260426) is vulnerable to an authentication bypass via capture-replay. Commands transmitted between the mobile application and the charger via Bluetooth Low Energy (BLE) or Wi-Fi (UDP) lack encryption and integrity protection. An attacker within local network range can intercept these unencrypted UDP packets and replay or modify them to manipulate charging parameters, including duration, current, and power states. The attack is considered complex as it requires local network proximity and the ability to intercept specific traffic. As of April 2026, the vendor has acknowledged the report and is reviewing the findings.
Affected products
- Besen BS20 EV Charging Station up to 20260426
Timeline
- 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged.
- 2026-05-24: advisory: CVE published.