EV Energy ev.energy
EV Energy ev.energy charging station software contains four critical vulnerabilities affecting all versions, including missing WebSocket authentication (CVE-2026-27772), lack of rate limiting on authentication attempts (CVE-2026-24445), insufficient session expiration with predictable identifiers (CVE-2026-26290), and publicly exposed charging station credentials (CVE-2026-25774). These flaws could allow attackers to gain unauthorized administrative control over charging infrastructure, perform denial-of-service attacks, and manipulate charging network operations globally. The vendor has not responded to CISA's coordination requests.
Summary
EV Energy ev.energy charging station software contains four critical vulnerabilities affecting all versions, including missing WebSocket authentication (CVE-2026-27772), lack of rate limiting on authentication attempts (CVE-2026-24445), insufficient session expiration with predictable identifiers (CVE-2026-26290), and publicly exposed charging station credentials (CVE-2026-25774). These flaws could allow attackers to gain unauthorized administrative control over charging infrastructure, perform denial-of-service attacks, and manipulate charging network operations globally. The vendor has not responded to CISA's coordination requests.
Indicators of Compromise
- cve — CVE-2026-27772
- cve — CVE-2026-24445
- cve — CVE-2026-26290
- cve — CVE-2026-25774