Back to Feed
VulnerabilitiesMar 3, 2026

ePower epower.ie

ePower epower.ie charging station software contains four critical vulnerabilities affecting all versions, including missing authentication on WebSocket endpoints, lack of rate limiting on authentication attempts, insufficient session expiration, and publicly exposed credentials. These flaws enable attackers to gain unauthorized administrative control over charging stations, perform denial-of-service attacks, and manipulate charging infrastructure data. The vendor has not responded to CISA's coordination requests.

Summary

ePower epower.ie charging station software contains four critical vulnerabilities affecting all versions, including missing authentication on WebSocket endpoints, lack of rate limiting on authentication attempts, insufficient session expiration, and publicly exposed credentials. These flaws enable attackers to gain unauthorized administrative control over charging stations, perform denial-of-service attacks, and manipulate charging infrastructure data. The vendor has not responded to CISA's coordination requests.

Indicators of Compromise

  • cve — CVE-2026-22552
  • cve — CVE-2026-27778
  • cve — CVE-2026-24912
  • cve — CVE-2026-27770