CVE-2026-22099
Missing authentication for Bluetooth communication
| CVE | CVE-2026-22099 |
| Title | Missing authentication for Bluetooth communication |
| Credits |
|
| Affected products |
| Product |
Affected |
Unaffected |
Unknown |
|
EVbee DC-80
|
>=
0
to
< 1.5.4
(semver)
|
|
|
|
everything else |
|
|
| CVSS |
|
| References |
|
| Problem type(s) |
CWE-287 Improper Authentication
|
|
Date published
|
|
|
Last modified
|
16 Jul 2026 15:41 UTC
|
Description
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.
JSON version.