EVbee Service App and DC Quick Charger Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the NPC start endpoint of the web server running on port 8090. This issue affects the EVbee Service App versions prior to 1.4.710 and the DC Quick Charger Firmware versions prior to V1.5.1.

Impact

Exploitation of this vulnerability allows for command injection on the affected web server endpoint.

Remediation

Users are advised to update the EVbee Service App to version 1.4.710 or later and to ensure that the DC Quick Charging Station is connected to update the firmware to version V1.5.1 or later.

Added: Jul 13, 2026, 11:58 AM
Updated: Jul 13, 2026, 11:58 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.