Missing authentication for webserver endpoints
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.5%
exploitation probability
0.5%top 55% of all CVEs
observed exploitation
nono source reports it
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
EVbee · DC-80References
https://csirt.divd.nl/DIVD-2026-00001/