VYPR

OCPP WebSocket endpoint

by Cloudcharge.tech

CVEs (1)

  • CVE-2026-20781CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…