EVbee Service App and DC Quick Charger Command Injection Vulnerability in OCPP ReserveLogin Message

Vulnerability

A command injection vulnerability has been identified in the EVbee Service App and the DC Quick Charger Firmware, both prior to their respective latest versions. This vulnerability allows arbitrary operating system commands to be executed as root by manipulating the data value in the OCPP DataTransfer message 'ReserveLogin'.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the operating system with root privileges.

Remediation

Users are advised to update the EVbee Service App to version 1.4.710 or later and to ensure that the DC Quick Charging Station is updated to version 1.5.1 or later.

Added: Jul 13, 2026, 12:03 PM
Updated: Jul 13, 2026, 12:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
9.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.