CVE-2026-21635
Improper Access Control in EV Station Lite WiFi AutoLink
Publication date: 2026-01-05
Last updated on: 2026-01-05
Assigner: HackerOne
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| unknown_vendor | ev_station_lite | to 1.5.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Access Control issue in the EV Station Lite (version 1.5.2 and earlier). It allows a malicious actor within Wi-Fi range to exploit the WiFi AutoLink feature on a device that was originally adopted only via Ethernet, potentially gaining unauthorized access.
How can this vulnerability impact me? :
The vulnerability could allow an attacker nearby to access the device via Wi-Fi even if it was intended to be accessed only through Ethernet, potentially leading to unauthorized access or control of the device. This could compromise device security and operations.