EVbee Service App
- < 1.4.710
A vulnerability exists in the EVbee Service App versions prior to 1.4.710 and in the DC Quick Charger Firmware versions prior to V1.5.1. The issue arises because the firmware update mechanism lacks cryptographic signature validation. This flaw enables individuals with access to the firmware update feature to upload arbitrary files, potentially leading to unauthorized code execution.
Exploitation of this vulnerability allows for arbitrary code execution on the affected device.
Users are advised to update the EVbee Service App to the latest version and ensure that the DC Quick Charging Station is connected to receive the firmware update.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.