{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "cveMetadata": {
    "cveId": "CVE-2026-22101",
    "assignerOrgId": "00000000-0000-4000-9000-000000000000",
    "requesterUserId": "00000000-0000-4000-9000-000000000000",
    "serial": 1,
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "00000000-0000-4000-9000-000000000000"
      },
      "title": "Sensitive information leak through hidden menu",
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "cweId": "CWE-200",
              "description": "CWE-200",
              "type": "CWE"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "EVbee",
          "product": "DC-80",
          "versions": [
            {
              "status": "affected",
              "version": "unknown"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password."
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV4_0": {
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "subConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "vulnAvailabilityImpact": "NONE",
            "subAvailabilityImpact": "NONE",
            "exploitMaturity": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "valueDensity": "NOT_DEFINED",
            "vulnerabilityResponseEffort": "NOT_DEFINED",
            "providerUrgency": "NOT_DEFINED",
            "version": "4.0",
            "baseSeverity": "MEDIUM",
            "baseScore": 5.1,
            "vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Wilco van Beijnum (ElaadNL)",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "Jeroen van der Ham-de Vos (DIVD)",
          "type": "analyst"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 0.5.0"
      }
    }
  }
}