CVE-2026-27770 describes a vulnerability where charging station authentication identifiers are publicly exposed through web-based mapping platforms, affecting an unspecified range of products. This medium-severity vulnerability (CVSS 6.5) can be exploited remotely with low complexity, potentially leading to unauthorized access to sensitive information (C:L, I:L) without user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered minimal community discussion and media coverage, indicating limited public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| EPower | Epower.Ie | All versionsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.