CVE-2026-9395
Last modified
CVE-2026-9395 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation leads to insufficiently protected credentials. The attack needs to be initiated within the local network. The original disclosure mentions, that "[t]hese vulnerabilities have been reported to Besen and we have received their acknowlegement that they are reviewing this as of April 2026."
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-9395?
How severe is CVE-2026-9395?
How do I fix CVE-2026-9395?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-93921SiYuan versions through 3.8.4 fail to enforce publish access…4.3
- CVE-2026-93922SiYuan through 3.8.4 renders notebook names as raw HTML in t…8.8
- CVE-2026-93923SiYuan through 3.8.4 fails to escape heading style attribute…8.8
- CVE-2026-93928Authentication Bypass Using an Alternate Path or Channel vul…7.3
- CVE-2026-9393A vulnerability was found in H3C Magic B0 up to 100R002. Thi…8.8
- CVE-2026-9394A vulnerability was determined in Besen BS20 EV Charging Sta…3.1
- CVE-2026-93952VeloCloud Orchestrator (VCO) on-prem has a security issue wh…10
- CVE-2026-93954A security vulnerability has been detected in grimmory-tools…4.3
- CVE-2026-93955A vulnerability was detected in grimmory-tools grimmory up t…4.3
- CVE-2026-93956A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Aff…3.5
- CVE-2026-93957A vulnerability has been found in olivier-ls PHP-FTS up to 1…4.3
- CVE-2026-93958A vulnerability was found in D-Link R95 BE9500_1.00.16. This…9.1
Are you affected by CVE-2026-9395?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
