CISA: Monta EV charging platform has four flaws, worst rated CVSS 9.4
CISA published advisory ICSA-26-274-02 covering four vulnerabilities in all versions of the Monta EV charging platform. The worst (CVE-2026-95102, CVSS 9.4) is missing authentication on OCPP WebSocket endpoints, letting attackers impersonate charging stations using publicly visible station IDs.
- CVE-2026-95102: no OCPP WebSocket auth, CVSS 9.4
- CVE-2026-97363: unlimited auth attempts enable brute force and DoS, CVSS 7.5
- CVE-2026-97212: same session ID can connect to multiple endpoints, CVSS 7.3
- CVE-2026-93474: station identifiers exposed via public mapping platforms
Read next
Security