CVE-2026-95102
Received Received - Intake

Unauthenticated WebSocket Access in EV Charging Stations

Vulnerability report for CVE-2026-95102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: ICS-CERT

Description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves WebSocket endpoints that do not have proper authentication. Attackers can exploit this to impersonate charging stations, gaining unauthorized access to sensitive data or performing unauthorized actions. This lack of authentication can lead to privilege escalation and compromise the entire system's security.

Detection Guidance

Detecting this vulnerability requires checking WebSocket endpoints for missing authentication. Use network scanning tools like nmap to identify open WebSocket ports (typically 80, 443, or custom ports). Commands: nmap -p 80,443 --script http-websocket <target> or curl -i -N -H 'Connection: Upgrade' -H 'Upgrade: websocket' <target>. Inspect responses for lack of authentication prompts or error messages indicating open access.

Impact Analysis

Attackers could gain control over charging stations, steal sensitive data, or perform actions without authorization. This could disrupt services, lead to financial losses, or expose private information, depending on the system's use case.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by allowing unauthorized access to sensitive data. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance with data protection regulations.

Mitigation Strategies

Immediately restrict access to WebSocket endpoints by implementing strong authentication (e.g., OAuth, API keys). Update server configurations to enforce TLS encryption. Disable unused WebSocket endpoints and apply network segmentation to isolate charging station systems. Monitor logs for unauthorized access attempts and patch any exposed endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95102. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart