EVbee Service App
- < 1.4.710
A vulnerability allowing arbitrary file overwriting has been identified in the EVbee Service App and the DC Quick Charger Firmware, both prior to their respective latest versions. This issue arises from a web server endpoint that accepts file names in the Content-Disposition header without proper validation. Exploitation of this vulnerability could lead to a denial-of-service by overwriting critical system files or allow remote code execution by replacing shell scripts that could be executed through other means.
Exploitation of this vulnerability could cause a denial-of-service by overwriting system files or enable remote code execution by replacing shell scripts that could be executed through other means.
Users are advised to update the EVbee Service App and ensure that the DC Quick Charging Station is connected to receive the latest firmware update.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.