GHSA-cvv7-f8m3-cjxxLowCVSS 3.5
A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation leads to insufficiently protected credentials. The attack needs to be initiated within the local network. The original disclosure mentions, that "[t]hese vulnerabilities have been reported to Besen and we have received their acknowlegement that they are reviewing this as of April 2026."
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-9395
- https://github.com/carfeii/besen#finding-2-cleartext-credential-exposure-via-ble-and-udp-in-besen-home-ev-charging-station
- https://vuldb.com/submit/813572
- https://vuldb.com/vuln/365376
- https://vuldb.com/vuln/365376/cti
- https://github.com/advisories/GHSA-cvv7-f8m3-cjxx