CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
CybersecurityEV & Infrastructure

EV Energy charging platform flaws allow full grid hijack with no patch

CISA has reported multiple vulnerabilities in EV Energy’s electric vehicle charging platform that could allow attackers to gain full administrative control over charging networks, with no official patches available.

CarThreat Staff
Last updated: July 18, 2026 7:24 am
By
ctadmin
2 Min Read
SHARE

CISA has reported multiple vulnerabilities in EV Energy’s electric vehicle charging platform that could allow attackers to gain full administrative control over charging networks, with no official patches available from the vendor.

The most critical flaw, CVE-2026-27772, carries a CVSS score of 9.4 and involves a missing authentication mechanism in WebSocket endpoints. An unauthenticated attacker can connect to the Open Charge Point Protocol WebSocket using a discovered station identifier, then send and receive commands as if they were a legitimate charger. This grants full infrastructure control including the ability to disrupt charging services, corrupt usage data, and potentially damage physical hardware.

CVE-2026-24445 describes a rate-limiting deficiency in the WebSocket API that enables brute-force attacks and denial-of-service scenarios by suppressing or misrouting legitimate charger telemetry. Attackers can exploit this to lock out genuine charging stations or flood the backend with malicious traffic.

Two additional vulnerabilities compound the risk. CVE-2026-26290 involves insufficient session expiration, allowing multiple connections to reuse the same predictable session identifier for hijacking or shadowing attacks. CVE-2026-25774 is an information disclosure flaw where charging station authentication identifiers are publicly accessible through web-based mapping platforms, providing attackers with the credentials needed to exploit the WebSocket vulnerabilities.

All versions of the ev.energy platform are affected. Because the vendor did not respond to CISA’s coordination requests, no software patches exist. CISA recommends organizations isolate control systems from the internet, deploy firewalls, and use VPNs for any required remote management as compensatory measures.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Authentication BypassCharging InfrastructureCISACVE-2026-27772EV chargerEV EnergyOCPPWebSocket
SOURCES:CISABeyondMachines
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Qualcomm critical Wi-Fi flaw reaches car cockpit chips

By
ctadmin
August 7, 2026
CybersecurityPolicy & Compliance

EU issues 2026 mandate for connected vehicle cybersecurity requirements

By
ctadmin
July 18, 2026
My Eicher fleet API flaws exposed 676,000 trucks to takeover
Cybersecurity

My Eicher fleet API flaws exposed 676,000 trucks to takeover

By
ctadmin
August 1, 2026
Cybersecurity

Seoul consortium builds one chip to shield cars from quantum threats

By
ctadmin
August 19, 2026
Cybersecurity

Dealer-installed alarm exposes 2 million cars to Bluetooth theft attacks

By
ctadmin
July 21, 2026
Cybersecurity

Risk scoring framework cuts attack success in autonomous vehicles

By
ctadmin
August 13, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?