WebSocket Authentication Vulnerability in Charging Stations by CISA
CVE-2026-95102

9.3CRITICAL

Key Information:

Vendor

Monta

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-95102?

The WebSocket endpoints in specific charging station models lack essential authentication mechanisms, enabling attackers to impersonate these stations. This oversight allows malicious actors to access sensitive data and perform actions without appropriate permissions, leading to potential privilege escalation and a severe compromise of the overall system's security.

Affected Version(s)

monta.app All versions

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.