Junglewise Threat Intelligence

CVE-2026-9398: Besen BS20 EV Charging Station authentication bypass in BLE/WiFi

CVE-2026-9398 · Severity: low · CVSS 3.1 · Published 2026-05-24

Technologies: Besen BS20 EV Charging Station. Vendors: Besen.

Executive brief

The Besen BS20 EV Charging Station is a home electric vehicle charger. A security flaw in its communication protocols allows an attacker on the same local network to intercept and replay commands. This could allow an unauthorized person to tamper with charging settings, such as starting or stopping a charge or changing the power levels.

Technical details

The Besen BS20 EV Charging Station (up to version 20260426) is vulnerable to an authentication bypass via capture-replay. Commands transmitted between the mobile application and the charger via Bluetooth Low Energy (BLE) or Wi-Fi (UDP) lack encryption and integrity protection. An attacker within local network range can intercept these unencrypted UDP packets and replay or modify them to manipulate charging parameters, including duration, current, and power states. The attack is considered complex as it requires local network proximity and the ability to intercept specific traffic. As of April 2026, the vendor has acknowledged the report and is reviewing the findings.

Affected products

  • Besen BS20 EV Charging Station up to 20260426

Timeline

  • 2026-04-26: disclosed: Vulnerabilities reported to vendor and acknowledged.
  • 2026-05-24: advisory: CVE published.

References

Related threats