Critical severity9.4NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-40702
CVE-2026-40702
Description
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
1- EVoke Systems Charging Station Management SystemCISA ICS Advisories