CVE-2026-22097

CRITICAL

EVbee DC-80 - Missing Firmware Signature Validation Remote Code Execution

Title source: manual
STIX 2.1

Description

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://csirt.divd.nl/DIVD-2026-00001/

Scores

CVSS v4 9.3
EPSS 0.0021
EPSS Percentile 11.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
EVbee/DC-80 < 1.5.1
Published Jul 13, 2026
Tracked Since Jul 13, 2026