VYPR

OCPP WebSocket endpoint

by SWTCH Energy

CVEs (1)

  • CVE-2026-27767CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…