PT-2026-57670 · Unknown · Evbee Service

CVE-2026-22093

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions EVbee Service version 1.4.101.00
Description The Android application uses HTTPS for communication but fails to validate the server certificate. This flaw allows an attacker positioned on the network path to intercept and manipulate traffic between the app and the server. Additionally, the communication is weakly encrypted using the RC4 stream cipher with a hardcoded key, which can be bypassed to gain access to sensitive data, including access codes for charging stations.
Recommendations Update EVbee Service version 1.4.101.00 to a version that implements proper SSL/TLS certificate validation and replaces the hardcoded RC4 encryption with a secure encryption standard.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22093

Affected Products

Evbee Service