EVbee Service App
- < 1.4.710
A command injection vulnerability has been identified in the NPC start endpoint of the web server running on port 8090. This issue affects the EVbee Service App versions prior to 1.4.710 and the DC Quick Charger Firmware versions prior to V1.5.1.
Exploitation of this vulnerability allows for command injection on the affected web server endpoint.
Users are advised to update the EVbee Service App to version 1.4.710 or later and to ensure that the DC Quick Charging Station is connected to update the firmware to version V1.5.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.