Skip to content

Executive Summary

Vulnerabilities exist in monta.app across multiple versions and affect WebSocket endpoints, allowing for unauthorized access and potential denial-of-service attacks against charging stations. Specific vulnerabilities include missing authentication for critical functions, improper restriction of excessive authentication attempts, insufficient session expiration, and exposure of charging station identifiers. Mitigation efforts involve implementing rate limiting and connection throttling at the WebSocket layer, handling duplicate connection attempts according to OCPP specifications, and encouraging the adoption of secured protocols like OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS). The identified risks are categorized with various CVSS scores, ranging from Medium to Critical severity.

Facts Only

monta.app versions:all/* are affected by CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474.
CVE-2026-95102 involves WebSocket endpoints lacking proper authentication, allowing impersonation of charging stations.
CVE-2026-97363 concerns the lack of rate limiting on the WebSocket API, potentially enabling denial-of-service or brute-force attacks.
CVE-2026-97212 relates to the use of charging station identifiers for session association allowing multiple endpoints to connect with the same identifier.
CVE-2026-93474 indicates that charging station authentication identifiers are publicly accessible via web mapping platforms.
Mitigations include implementing rate limiting and connection throttling at the WebSocket layer, handling duplicate connections per OCPP specifications, and supporting OCPP 1.6 Security Profile 2.

Full Take

The mechanism described involves a fundamental tension between operational necessity—allowing systems to communicate securely—and security requirements concerning access control. The pattern of vulnerability stems from a failure to implement layered security controls at the communication layer (WebSockets), where trust boundaries are improperly defined, specifically regarding authentication and session management tied to charging station identifiers. The presence of multiple related CVEs (authentication bypass, rate limiting failures, session predictability) suggests a systemic oversight in the implementation or design choices for handling sensitive endpoint interactions within critical infrastructure systems. The mitigation strategy relies heavily on operational countermeasures—rate limiting and protocol adherence—rather than fixing the root architectural flaw of unauthenticated defaults. This raises questions about the inherent trust placed in the communication channels used by energy and transportation control systems, especially when public-facing identifiers are involved. What structures exist within these infrastructure environments that allow for such critical functions to bypass standard authentication checks? How does reliance on dynamic throttling manage the risk when the underlying identification mechanism itself is exposed?

From the original · CISA Alerts

Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Read the full story at cisa.gov

Sentinel — Human

Confidence

This text functions as a highly structured, technically dense vulnerability advisory, characteristic of official cybersecurity reporting rather than synthetic content.

Signals Detected
low severity: Slightly complex structure; technical enumeration suggests structured reporting rather than pure LLM prose.
low severity: High focus on enumerated CVEs and mitigation steps, typical of official advisories, but the summary is direct and informative.
medium severity: Strict adherence to structured data (tables for CVEs, clear enumeration of mitigations) suggests template-driven information presentation.
low severity: The content is highly technical and grounded in specific reference numbers (CVEs, CWEs, vendor actions), typical of factual security advisories, not creative narrative fabrication.
Human Indicators
The inclusion of explicit references to CISA, OCPP standards, and specific CVE/CWE identifiers suggests derivation from official security advisories or technical documentation.
Monta monta.app | Huntaegis