CVE-2026-20895

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/02/2026
Last modified:
27/02/2026

Description

The WebSocket backend uses charging station identifiers to uniquely <br /> associate sessions but allows multiple endpoints to connect using the <br /> same session identifier. This implementation results in predictable <br /> session identifiers and enables session hijacking or shadowing, where <br /> the most recent connection displaces the legitimate charging station and<br /> receives backend commands intended for that station. This vulnerability<br /> may allow unauthorized users to authenticate as other users or enable a<br /> malicious actor to cause a denial-of-service condition by overwhelming <br /> the backend with valid session requests.