PatchSiren cyber security CVE debrief
CVE-2026-9396 Besen CVE debrief
A low-severity vulnerability (CVSS 4.0: 2.9) affecting Besen BS20 EV Charging Station firmware versions up to 20260426. The flaw resides in the Firmware Version Check component, where improper restriction of rendered UI layers (CWE-1021) can be exploited remotely with high attack complexity. The vulnerability enables UI spoofing through manipulation of firmware version verification mechanisms. The vendor acknowledged receipt of the disclosure and indicated active review as of April 2026. No known exploitation in the wild or ransomware campaign association has been identified.
- Vendor
- Besen
- Product
- BS20 EV Charging Station
- CVSS
- LOW 2.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-24
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-24
- Advisory updated
- 2026-07-23
Who should care
Operators of Besen BS20 EV charging infrastructure, critical infrastructure security teams, IoT/OT security practitioners, electric vehicle fleet managers, and organizations with public or workplace charging deployments
Technical summary
The Besen BS20 EV Charging Station contains an improper restriction of rendered UI layers vulnerability (CWE-1021) in its Firmware Version Check component. An attacker with network access can manipulate firmware version verification to spoof UI elements, potentially misleading users or administrators about device state. The attack requires high complexity to execute and results in low integrity impact per CVSS 4.0 scoring. The vulnerability affects devices running firmware up to version 20260426. Remote exploitation is possible without authentication, though the difficult exploitation path reduces immediate risk. The researcher disclosed findings to Besen with vendor acknowledgment of active review as of April 2026; no patch availability timeline has been published.
Defensive priority
low
Recommended defensive actions
- Monitor Besen security advisories for firmware updates addressing the BS20 EV Charging Station
- Review EV charging station UI authentication and firmware verification implementations for improper layer restriction weaknesses
- Implement network segmentation for EV charging infrastructure to limit remote attack exposure
- Verify firmware integrity through out-of-band validation mechanisms independent of device-reported version strings
- Contact Besen support to confirm remediation timeline and obtain patched firmware when available
Evidence notes
Vulnerability disclosed via VulDB with reference to GitHub research repository. Vendor acknowledgment documented in disclosure. NVD status marked as Deferred as of 2026-05-26. CVSS 4.0 vector indicates network attack vector with high attack complexity, no privileges required, and low integrity impact to the vulnerable system.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9396 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9396
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9396 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9396
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/carfeii/besen
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/813575
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/365377
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/365377/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.