CVE-2026-32663

7.3

IGL-Technologies · eParking.fi

The IGL-Technologies eParking.fi WebSocket backend allows session hijacking or shadowing due to insufficient validation of charging station identifiers.

Executive summary

A critical session management flaw in the IGL-Technologies eParking.fi WebSocket backend allows unauthenticated attackers to hijack or shadow charging station sessions, potentially leading to unauthorized command execution.

Vulnerability

The vulnerability exists in the WebSocket backend, which fails to securely validate charging station identifiers. This allows an unauthenticated attacker to connect using a valid identifier, displacing the legitimate session and gaining the ability to interact with backend commands intended for the original device.

Business impact

The exploitation of this vulnerability permits unauthorized actors to impersonate legitimate charging stations, which could result in unauthorized administrative actions or service disruptions. Given the CVSS score of 7.3, this represents a high-risk scenario for infrastructure integrity and operational availability. Failure to remediate could lead to widespread denial-of-service or the compromise of remote management functions across deployed charging hardware.

Remediation

Immediate Action: Update the eParking.fi OCPP servers to the latest version provided by IGL-Technologies to implement device-level whitelisting and enforce modern security profiles.

Proactive Monitoring: Implement network monitoring to detect abnormal connection patterns, such as multiple endpoints attempting to authenticate with a single identifier, and monitor access logs for unexpected session displacement events.

Compensating Controls: If immediate patching is not feasible, restrict network access to the WebSocket backend to known, trusted IP ranges and employ rate-limiting at the edge to mitigate potential denial-of-service attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The reliance on predictable charging station identifiers for session management presents a significant security gap. Organizations utilizing IGL-Technologies eParking.fi should prioritize the application of the vendor-supplied updates immediately to enable mandatory device authentication and rate-limiting controls. Failure to secure these endpoints leaves critical charging infrastructure susceptible to remote session hijacking and operational degradation.

Sources

Originally found and disclosed by Khaled Sarieddine and Mohammad Ali Sayed reported this vulnerability to CISA., per the CVE Program record.