CVE-2026-9395

A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation leads to insufficiently protected credentials. The attack needs to be initiated within the local network. The original disclosure mentions, that "[t]hese vulnerabilities have been reported to Besen and we have received their acknowlegement that they are reviewing this as of April 2026."
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue identificada en la estación de carga de vehículos eléctricos Besen BS20 hasta el 20260426. Afectada es una función desconocida del componente BLE/UDP. La manipulación conduce a credenciales insuficientemente protegidas. El ataque necesita ser iniciado dentro de la red local. La divulgación original menciona que 'Estas vulnerabilidades han sido reportadas a Besen y hemos recibido su acuse de recibo de que están revisando esto a fecha de abril de 2026.'

24 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-24 20:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9395

Mitre link : CVE-2026-9395

CVE.ORG link : CVE-2026-9395


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials