Skip to main content
CVE Vulnerability Database

CVE-2026-9394: Besen BS20 Auth Bypass Vulnerability

CVE-2026-9394 is an authentication bypass flaw in Besen BS20 EV Charging Station affecting the Bluetooth Low Energy Handler with weak password requirements. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-9394 Overview

CVE-2026-9394 affects the Besen BS20 Electric Vehicle (EV) Charging Station through firmware version 20260426. The vulnerability resides in the Bluetooth Low Energy (BLE) Handler component and stems from weak password requirements [CWE-521]. An attacker within Bluetooth radio range of the charging station can leverage the weak authentication mechanism to interact with the device.

Exploitation requires adjacent network access and high attack complexity, which limits practical exploitability. The original disclosure indicates Besen acknowledged the report and was reviewing the issue as of April 2026.

Critical Impact

An attacker within BLE range can exploit weak password requirements on the Besen BS20 EV Charging Station, with limited confidentiality impact and no integrity or availability impact.

Affected Products

  • Besen BS20 EV Charging Station firmware up to 20260426
  • Bluetooth Low Energy (BLE) Handler component
  • Besen Home EV Charging Station product line (per disclosure reference)

Discovery Timeline

  • April 2026 - Vulnerability reported to Besen; vendor acknowledged review
  • 2026-05-24 - CVE-2026-9394 published to NVD
  • 2026-05-26 - Last updated in NVD database

Technical Details for CVE-2026-9394

Vulnerability Analysis

The Besen BS20 EV Charging Station exposes a Bluetooth Low Energy (BLE) interface used for local device management. The BLE Handler enforces weak password requirements, classified under [CWE-521]. This allows an adjacent attacker to authenticate against the charger using credentials that fall below acceptable cryptographic strength.

The scope of impact is constrained. The vulnerability yields limited confidentiality impact with no integrity or availability consequences. Successful exploitation requires the attacker to be within BLE radio range of the target charging station.

The attack is rated as high complexity, indicating that exploitation depends on conditions outside the attacker's direct control. Public disclosure references on GitHub describe the weak authentication finding for the Besen Home EV Charging Station via BLE.

Root Cause

The root cause is insufficient password strength enforcement in the BLE authentication path. The device permits credentials that do not satisfy modern password complexity, length, or entropy requirements. Attackers within radio range can attempt authentication against the BLE service with reduced effort compared to a properly hardened authentication mechanism.

Attack Vector

The attack vector is Adjacent Network, specifically Bluetooth Low Energy. An attacker must be in physical proximity to the EV charging station to reach the BLE radio. After scanning for the target device, the attacker connects to the BLE service and attempts authentication using guessable or low-entropy credentials.

No verified exploit code is publicly available for CVE-2026-9394. The vulnerability is documented in the GitHub Weak Auth Mechanism disclosure and the VulDB Vulnerability #365375 record.

Detection Methods for CVE-2026-9394

Indicators of Compromise

  • Unexpected BLE pairing or connection events to the charging station outside operator activity windows
  • Repeated failed BLE authentication attempts followed by a successful login
  • Configuration changes on the BS20 charger that do not correlate with authorized user sessions

Detection Strategies

  • Monitor BLE advertising and connection logs on managed EV charging infrastructure for anomalous client MAC addresses
  • Correlate physical access logs with BLE session timestamps to identify unauthorized proximity events
  • Capture and review device-side audit logs from the Besen BS20 management interface for credential change events

Monitoring Recommendations

  • Deploy Bluetooth-aware sensors near deployed EV chargers to detect rogue BLE scanners and connection attempts
  • Forward charger management logs to a centralized SIEM or data lake for retention and historical analysis
  • Alert on configuration drift in the BS20 firmware and BLE service settings

How to Mitigate CVE-2026-9394

Immediate Actions Required

  • Change the BLE password on each Besen BS20 unit to the maximum length and complexity supported by the device
  • Restrict physical access to deployed charging stations to reduce BLE proximity exposure
  • Disable the BLE management interface when not actively required for provisioning or maintenance

Patch Information

No vendor patch has been published at the time of NVD entry. Besen acknowledged review of the disclosure as of April 2026. Operators should monitor the VulDB Vulnerability #365375 record and Besen vendor channels for firmware updates that address weak password enforcement in the BLE Handler.

Workarounds

  • Power down or BLE-disable charging stations during periods of low utilization to reduce exposure window
  • Enforce administrative procedures requiring strong, unique passwords on every BS20 unit during commissioning
  • Deploy BLE jamming-resistant physical enclosures or signal-attenuating installation locations where feasible
  • Maintain an inventory of BS20 firmware versions and prioritize replacement of units that cannot accept strong credentials

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.