Skip to the content.

CVE-2026-22093

Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app

CVE CVE-2026-22093
Title Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
Credits
Affected products
Product Affected Unaffected Unknown
EVbee EVbee Service on Android >= 0 to < 1.4.7.10 (semver)
everything else
CVSS
Base score 9.5 - CRITICAL
Attack Vector NETWORK
Attack Complexity> LOW
Attack Requirements PRESENT
Privileges Required NONE
Confidentiality Impact
Vulnerable system HIGH Subsequent systems HIGH
Integrity Impact
Vulnerable system HIGH Subsequent systems HIGH
Availability Impact
Vulnerable system NONE Subsequent systems LOW
Safety impact NOT_DEFINED
Automatable NOT_DEFINED
Recovery NOT_DEFINED
Value Density NOT_DEFINED
Vulnerability Response effort NOT_DEFINED
Provider Urgency NOT_DEFINED
References
Problem type(s) CWE-295 Improper Certificate Validation
Date published
Last modified 16 Jul 2026 15:41 UTC

Description

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations.

This issue affects EVbee Service: v1.4.101.00.



JSON version.