Executive Summary
Facts Only
monta.app versions:all/* are affected by CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474.
CVE-2026-95102 involves WebSocket endpoints lacking proper authentication, allowing impersonation of charging stations.
CVE-2026-97363 concerns the lack of rate limiting on the WebSocket API, potentially enabling denial-of-service or brute-force attacks.
CVE-2026-97212 relates to the use of charging station identifiers for session association allowing multiple endpoints to connect with the same identifier.
CVE-2026-93474 indicates that charging station authentication identifiers are publicly accessible via web mapping platforms.
Mitigations include implementing rate limiting and connection throttling at the WebSocket layer, handling duplicate connections per OCPP specifications, and supporting OCPP 1.6 Security Profile 2.
Full Take
From the original · CISA Alerts
Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.Read the full story at cisa.gov
Sentinel — Human
This text functions as a highly structured, technically dense vulnerability advisory, characteristic of official cybersecurity reporting rather than synthetic content.
