Monta EV charging flaws: chargers can be impersonated (CVSS 9.4)
TL;DR: CISA advisory ICSA-26-274-02 (October 1, 2026) lists four vulnerabilities in all versions of the Monta EV charging platform (monta.app), the worst rated CVSS 9.4. The OCPP WebSocket endpoints do not authenticate charging stations, and station IDs are publicly visible. Anyone operating chargers through Monta should enable OCPP 1.6 Security Profile 2 (Basic Auth over TLS) with a unique password per station as soon as possible. CVE Weakness CVSS v3.1 CVE-2026-95102 Missing authentication on OCPP WebSocket endpoints (CWE-306) – attackers can impersonate a charging station 9.4 CVE-2026-97363
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in