Vulnerabilities in EVbee
9 resultsVexday analysis
EVbee apresenta 9 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 7 delas classificadas como críticas (CVSS alto), predominantemente relacionadas a injeção de comandos (CWE-77). Embora nenhuma esteja sob exploração ativa conhecida no momento, o volume recente de críticas e a natureza da fraqueza dominante indicam risco elevado que demanda remediação urgente.
CVE-2026-22103CRITICALCommand injection in NPC start web endpointEPSS 1.4%CVE-2026-22095CRITICALCommand injection in diagnosis web endpointEPSS 1.4%CVE-2026-22100HIGHComnand injection in OCPP ReserveLogin messageEPSS 1.1%CVE-2026-22096CRITICALMissing authentication for webserver endpointsEPSS 0.5%CVE-2026-22102CRITICALArbitrary file overwrite through certificate update functionalityEPSS 0.5%CVE-2026-22098CRITICALSensitive information is written to logsEPSS 0.4%CVE-2026-22097CRITICALMissing firmware validation allows remote code executionEPSS 0.3%CVE-2026-22099HIGHMissing authentication for Bluetooth communicationEPSS 0.3%CVE-2026-22093CRITICALAdversary-in-the-Middle (AitM) attack vulnerability in EVbee Service appEPSS 0.3%