Back to Feed
VulnerabilitiesFeb 26, 2026

EV Energy ev.energy

EV Energy ev.energy charging station software contains four critical vulnerabilities affecting all versions, including missing WebSocket authentication (CVE-2026-27772), lack of rate limiting on authentication attempts (CVE-2026-24445), insufficient session expiration with predictable identifiers (CVE-2026-26290), and publicly exposed charging station credentials (CVE-2026-25774). These flaws could allow attackers to gain unauthorized administrative control over charging infrastructure, perform denial-of-service attacks, and manipulate charging network operations globally. The vendor has not responded to CISA's coordination requests.

Summary

EV Energy ev.energy charging station software contains four critical vulnerabilities affecting all versions, including missing WebSocket authentication (CVE-2026-27772), lack of rate limiting on authentication attempts (CVE-2026-24445), insufficient session expiration with predictable identifiers (CVE-2026-26290), and publicly exposed charging station credentials (CVE-2026-25774). These flaws could allow attackers to gain unauthorized administrative control over charging infrastructure, perform denial-of-service attacks, and manipulate charging network operations globally. The vendor has not responded to CISA's coordination requests.

Indicators of Compromise

  • cve — CVE-2026-27772
  • cve — CVE-2026-24445
  • cve — CVE-2026-26290
  • cve — CVE-2026-25774