CVE-2026-25851
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
27/02/2026
Last modified:
27/02/2026
Description
WebSocket endpoints lack proper authentication mechanisms, enabling <br />
attackers to perform unauthorized station impersonation and manipulate <br />
data sent to the backend. An unauthenticated attacker can connect to the<br />
OCPP WebSocket endpoint using a known or discovered charging station <br />
identifier, then issue or receive OCPP commands as a legitimate charger.<br />
Given that no authentication is required, this can lead to privilege <br />
escalation, unauthorized control of charging infrastructure, and <br />
corruption of charging network data reported to the backend.
Impact
Base Score 3.x
9.40
Severity 3.x
CRITICAL



