Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89g7-mr8w-m7x2

Опубликовано: 06 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.4

Описание

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

EPSS

Процентиль: 45%
0.00225
Низкий

9.3 Critical

CVSS4

9.4 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.4
nvd
около 1 месяца назад

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

EPSS

Процентиль: 45%
0.00225
Низкий

9.3 Critical

CVSS4

9.4 Critical

CVSS3

Дефекты

CWE-306