TL;DR: CISA advisory ICSA-26-274-02 (October 1, 2026) lists four vulnerabilities in all versions of the Monta EV charging platform (monta.app), the worst rated CVSS 9.4. The OCPP WebSocket endpoints do not authenticate charging stations, and station IDs are publicly visible. Anyone operating chargers through Monta should enable OCPP 1.6 Security Profile 2 (Basic Auth over TLS) with a unique password per station as soon as possible.
What CISA published
| CVE | Weakness | CVSS v3.1 |
|---|---|---|
| CVE-2026-95102 | Missing authentication on OCPP WebSocket endpoints (CWE-306) – attackers can impersonate a charging station | 9.4 |
| CVE-2026-97363 | No limit on authentication requests (CWE-307) – brute force and denial of service | 7.5 |
| CVE-2026-97212 | Multiple endpoints can connect with the same session ID (CWE-613) – may allow authenticating as other users | 7.3 |
| CVE-2026-93474 | Insufficiently protected credentials – charging station identifiers are publicly accessible via web-based mapping platforms | see advisory |
CISA lists the Energy and Transportation Systems sectors and worldwide deployment.
Why this is easy to abuse
A charger opens a WebSocket to the backend and identifies itself with its station ID. Without authentication, that ID is the only "secret" – and according to the advisory it is visible on public charging maps. In my assessment, an attacker could potentially connect as that charger with nothing more than a WebSocket client and perform unauthorized actions – and because authentication attempts are not limited, this could also enable denial of service.
Not a one-off
My take: this is likely an industry pattern rather than a one-off. OCPP has had security profiles for years – they just have to be switched on. Charging infrastructure is OT and deserves the same discipline as a substation.
Practical checklist for operators
Mapped to the SANS Five ICS Cybersecurity Critical Controls:
- Enable Security Profile 2 (CC4 Secure Remote Access): TLS with server certificate plus Basic Auth for every station, with a long, unique password unrelated to the station ID. Monta states in the advisory that it supports this.
- Close unauthenticated access (CC2 Defensible Architecture): Once all chargers are migrated, work with Monta to block unauthenticated connections for your stations. Monta says it will phase them out on a rolling basis – don't wait.
- Inventory and firmware (CC5 Risk-Based Vulnerability Management): Which charger talks to which backend, on which firmware? Does the firmware support Profile 2 at all?
- Monitor the charging operation (CC3 Network Visibility & Monitoring): Duplicate logins for the same station ID, connection drops and implausible meter values are red flags.
- Plan the incident (CC1 ICS Incident Response): Who shuts what down if chargers fail at scale or report false data? Who informs customers and authorities?
Mid-term, move to Security Profile 3 (mutual TLS with client certificates) or OCPP 2.0.1.
Regulatory angle (EU)
Recharging point operators are explicitly listed in Annex I (energy sector) of the NIS2 directive. Whether a specific operator is in scope depends on national law and size thresholds.
A German version with regional context for Bavaria, Salzburg and Tyrol will follow on OT-Cyber.de (Monday, October 5, 2026).
Max Gilg is an OT cybersecurity consultant based in Rosenheim, Germany (OT-Cyber.de).
Top comments (0)