CVE-2026-21635
Improper Access Control in EV Station Lite WiFi AutoLink
Publication date: 2026-01-05
Last updated on: 2026-01-05
Assigner: HackerOne
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| unknown_vendor | ev_station_lite | to 1.5.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability could allow an attacker nearby to access the device via Wi-Fi even if it was intended to be accessed only through Ethernet, potentially leading to unauthorized access or control of the device. This could compromise device security and operations.
Can you explain this vulnerability to me?
This vulnerability is an Improper Access Control issue in the EV Station Lite (version 1.5.2 and earlier). It allows a malicious actor within Wi-Fi range to exploit the WiFi AutoLink feature on a device that was originally adopted only via Ethernet, potentially gaining unauthorized access.