PT-2026-57670 · Unknown · Evbee Service
CVE-2026-22093
·
Published
2026-07-13
·
Updated
2026-07-13
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
EVbee Service version 1.4.101.00
Description
The Android application uses HTTPS for communication but fails to validate the server certificate. This flaw allows an attacker positioned on the network path to intercept and manipulate traffic between the app and the server. Additionally, the communication is weakly encrypted using the RC4 stream cipher with a hardcoded key, which can be bypassed to gain access to sensitive data, including access codes for charging stations.
Recommendations
Update EVbee Service version 1.4.101.00 to a version that implements proper SSL/TLS certificate validation and replaces the hardcoded RC4 encryption with a secure encryption standard.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evbee Service