CVE-2026-25778
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/02/2026
Last modified:
27/02/2026
Description
The WebSocket backend uses charging station identifiers to uniquely <br />
associate sessions but allows multiple endpoints to connect using the <br />
same session identifier. This implementation results in predictable <br />
session identifiers and enables session hijacking or shadowing, where <br />
the most recent connection displaces the legitimate charging station and<br />
receives backend commands intended for that station. This vulnerability<br />
may allow unauthorized users to authenticate as other users or enable a<br />
malicious actor to cause a denial-of-service condition by overwhelming <br />
the backend with valid session requests.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH



