EVbee Service App
- < 1.4.710
A vulnerability exists in the EVbee Service App and the DC Quick Charger Bluetooth communication, where authentication is not required for Bluetooth commands. This flaw allows for unauthorized actions such as accessing sensitive information, triggering reboots, or initiating a firmware update process. The issue is present in the EVbee Service App versions prior to 1.4.710 and in the DC Quick Charger Firmware versions prior to V1.5.1.
Exploitation of this vulnerability could lead to unauthorized actions being performed on the charging station, including sensitive information disclosure, unauthorized reboots, or unwarranted firmware updates.
Users are advised to update the EVbee Service App to version 1.4.710 or later and to ensure that the DC Quick Charging Station is connected to the internet to receive the firmware update to version V1.5.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.