Chargemap chargemap.com
Chargemap's charging station platform contains four critical vulnerabilities affecting all versions, including missing authentication on WebSocket endpoints (CVE-2026-25851), lack of rate limiting on authentication attempts (CVE-2026-20792), insufficient session management (CVE-2026-25711), and exposed credentials (CVE-2026-20791). These flaws enable unauthorized administrative control over charging infrastructure, privilege escalation, and denial-of-service attacks across energy and transportation sectors worldwide.
Summary
Chargemap's charging station platform contains four critical vulnerabilities affecting all versions, including missing authentication on WebSocket endpoints (CVE-2026-25851), lack of rate limiting on authentication attempts (CVE-2026-20792), insufficient session management (CVE-2026-25711), and exposed credentials (CVE-2026-20791). These flaws enable unauthorized administrative control over charging infrastructure, privilege escalation, and denial-of-service attacks across energy and transportation sectors worldwide.
Indicators of Compromise
- cve — CVE-2026-25851
- cve — CVE-2026-20792
- cve — CVE-2026-25711
- cve — CVE-2026-20791