CVE-2026-93474
Received Received - Intake

Charging Station Authentication IDs Exposed via Web Mapping

Vulnerability report for CVE-2026-93474, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: ICS-CERT

Description

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves charging station authentication identifiers being publicly accessible through web-based mapping platforms. This means unauthorized individuals could potentially view or obtain credentials used to authenticate charging stations.

Detection Guidance

This vulnerability involves publicly accessible charging station authentication identifiers via web-based mapping platforms. Detection requires checking if such identifiers are exposed online. Manually inspect web-based mapping platforms for charging station data or use search engines with specific queries to find exposed identifiers.

Impact Analysis

If exploited, attackers could misuse authentication identifiers to impersonate charging stations, disrupt services, or gain unauthorized access to charging infrastructure. This may lead to service disruptions or unauthorized usage of charging resources.

Compliance Impact

The vulnerability exposes charging station authentication identifiers publicly, which could lead to unauthorized access or misuse of sensitive data. This may impact compliance with regulations like GDPR (data protection) or HIPAA (health information privacy) by increasing risks of data breaches or unauthorized disclosures.

Mitigation Strategies

Restrict public access to charging station authentication identifiers by reviewing and updating web-based mapping platform settings. Ensure identifiers are not exposed in public datasets or APIs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93474. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart