CVE-2026-40702
EVoke · EVoke CSMS
The EVoke CSMS platform contains a critical vulnerability where WebSocket endpoints lack authentication, allowing attackers to impersonate charging stations and gain unauthorized system access.
Executive summary
A critical authentication failure in EVoke CSMS WebSocket endpoints allows attackers to impersonate charging stations, leading to potential unauthorized access and complete system compromise.
Vulnerability
The vulnerability stems from missing authentication mechanisms on WebSocket endpoints. This allows an unauthenticated attacker to inject traffic and impersonate legitimate charging stations, effectively bypassing security controls to execute unauthorized actions.
Business impact
With a CVSS score of 9.4, this vulnerability represents an extreme risk to the platform's security. Successful exploitation could result in the compromise of the charging infrastructure, unauthorized data access, and potential large-scale operational disruption, severely impacting both business revenue and physical asset security.
Remediation
Immediate Action: Apply the latest security update provided by EVoke to implement mandatory authentication for all WebSocket communications.
Proactive Monitoring: Monitor WebSocket traffic patterns for anomalous connection requests or suspicious commands originating from unauthorized or unexpected endpoints.
Compensating Controls: Deploy strict network segmentation and egress filtering to limit communication to only known, trusted charging station IP addresses.
Exploitation status
Public Exploit Available: False
Analyst recommendation
The high CVSS score underscores the severity of this authentication weakness. Organizations utilizing EVoke CSMS must prioritize this update to prevent unauthorized control over critical infrastructure components.