CVE-2026-25851

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
27/02/2026
Last modified:
27/02/2026

Description

WebSocket endpoints lack proper authentication mechanisms, enabling <br /> attackers to perform unauthorized station impersonation and manipulate <br /> data sent to the backend. An unauthenticated attacker can connect to the<br /> OCPP WebSocket endpoint using a known or discovered charging station <br /> identifier, then issue or receive OCPP commands as a legitimate charger.<br /> Given that no authentication is required, this can lead to privilege <br /> escalation, unauthorized control of charging infrastructure, and <br /> corruption of charging network data reported to the backend.