rootpwn

critical · CVSS v3 9.4 · CVSS v4 9.3

CVE-2026-95102

CVE-2026-95102 exposes WebSocket endpoints in charging station systems that lack authentication, allowing attackers to impersonate stations.

Overview

CVE-2026-95102 exposes WebSocket endpoints in charging station systems that lack authentication, allowing attackers to impersonate stations. This flaw can lead to unauthorized data access and control over charging operations. The vulnerability is rated critical with a CVSS v3 score of 9.4.

Description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

Impact

The lack of authentication violates confidentiality, integrity, and availability of charging station data and operations. Attackers can read sensitive data, modify charging commands, or disrupt service. Operators, fleet managers, and end‑users are directly impacted.

Remediation

Apply vendor‑issued patches that enforce authentication on WebSocket endpoints. If no patch is available, restrict WebSocket traffic to trusted IP ranges and enforce TLS with client certificates. Monitor for anomalous WebSocket connections and disable unused endpoints.

Risk context

The vulnerability is critical (CVSS 9.4) and poses an immediate threat to charging infrastructure. Defenders should prioritize remediation to prevent potential system compromise.

Affected products

  • EV charging station firmware
  • EV charging station API
  • charging station management platform
  • charging station WebSocket service
  • EV charging software

Scores

Severity
critical
CVSS v2
9.7
CVSS v3
9.4
CVSS v4
9.3
EPSS
—

websocket authentication charging-station critical iot

← All CVEs