WebSocket Authentication Flaw in Charging Station Software from Vendor XYZ
CVE-2026-40702

9.3CRITICAL

Key Information:

Vendor

Evoke

Vendor
CVE Published:
25 June 2026

What is CVE-2026-40702?

A security vulnerability exists in the WebSocket endpoints of charging station software from Vendor XYZ, where proper authentication mechanisms are absent. This flaw allows attackers to impersonate legitimate charging stations, facilitating unauthorized access to sensitive information. The lack of necessary authentication not only enables attackers to exploit this weakness but also potentially opens the door for privilege escalation, threatening the integrity and security of the entire system. Mitigation of this vulnerability is crucial to protecting against unauthorized actions and safeguarding sensitive data.

Affected Version(s)

EVoke CSMS All versions

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khaled Sarieddine and Mohammad Ali Sayed reported this vulnerability to CISA.
.