LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-25192

ctek · charge portal

Published
CVSS9.4
Severitycritical
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-25192

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-25192.