CVE-2026-54479
Received Received - Intake
Predictable Session Identifier in Charging Station Backend

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: ICS-CERT

Description
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the WebSocket backend that uses charging station identifiers to uniquely associate sessions. However, it allows multiple endpoints to connect using the same session identifier, resulting in predictable session identifiers.

Because of this, unauthorized users may be able to authenticate as other users or a malicious actor could cause a denial-of-service condition by overwhelming the backend with valid session requests.

Impact Analysis

This vulnerability can impact you by allowing unauthorized users to impersonate other users, potentially gaining access to restricted functions or data.

Additionally, it can enable attackers to launch denial-of-service attacks by flooding the backend with valid session requests, which could disrupt service availability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54479. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart