CVE-2026-22099: The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-22099
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-220990.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-22099 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for charging station does
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-44383: Multiple connections to the backend using the same charging station ID are allowed, which coul…nvd · 2026-07-10
- highCVE-2026-42952: Previously, there was no throttling on repeated authentication attempts to the charging statio…nvd · 2026-07-10
- criticalCVE-2026-20744: The charging station websocket endpoint accepts connections without proper authentication, whi…nvd · 2026-07-10
- criticalHydro-Québec Le Circuit Electrique charging station backendcisa · 2026-07-07
- highCVE-2026-54479: The WebSocket backend uses charging station identifiers to uniquely associate sessions but all…nvd · 2026-06-25
- mediumCVE-2026-44622: Charging station authentication identifiers are publicly accessible via web-based mapping plat…nvd · 2026-06-25
More from NVD Recent CVEs
- mediumCVE-2026-18573: A flaw was found in the keycloak-services component of Keycloak, which is used for managing au…2026-08-02
- mediumCVE-2026-18572: Keycloak provides authorization services that allow administrators to restrict access to resou…2026-08-02
- mediumCVE-2026-18571: A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permission…2026-08-02
- mediumCVE-2026-18570: A flaw was found in the full-scope-disabled client-policy executor within the keycloak-service…2026-08-02
- unknownCVE-2026-16540: The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict …2026-08-02