WebSocket API Vulnerability in Affected Product from Vendor
CVE-2026-24696

8.7HIGH

Key Information:

Vendor

Everon

Vendor
CVE Published:
6 March 2026

What is CVE-2026-24696?

The WebSocket Application Programming Interface in the affected product lacks necessary restrictions on the number of authentication requests, which exposes it to significant security risks. This vulnerability may be exploited by attackers to launch denial-of-service attacks, disrupting legitimate charger telemetry by either suppressing or mis-routing it. Additionally, without proper rate limiting, malicious actors could potentially execute brute-force attacks to gain unauthorized access, enhancing the urgency for mitigation measures.

Affected Version(s)

api.everon.io All versions

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khaled Sarieddine and Mohammad Ali Sayed reported this vulnerability to CISA.
.