CVE Explorer
CVE-2026-22093
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations.
This issue af
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Android"],"product":"EVbee Service","vendor":"EVbee","versions":[{"lessThan":"1.4.7.10","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3462eb75661ec535e1707299874836038d059b3e88b2f8e43faa657e92901143 · sha256:e5aef5d8c26e37c3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.5,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3462eb75661ec535e1707299874836038d059b3e88b2f8e43faa657e92901143 · sha256:e5aef5d8c26e37c3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-295","description":"CWE-295 Improper Certificate Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3462eb75661ec535e1707299874836038d059b3e88b2f8e43faa657e92901143 · sha256:e5aef5d8c26e37c3… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["third-party-advisory"],"url":"https://csirt.divd.nl/DIVD-2026-00001/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3462eb75661ec535e1707299874836038d059b3e88b2f8e43faa657e92901143 · sha256:e5aef5d8c26e37c3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.