Multiple Vulnerabilities Found in Monta EV Charging Software
CISA has identified critical vulnerabilities in Monta's electric vehicle charging station management software, monta.app, potentially allowing unauthorized control and disruption of services.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a significant advisory detailing multiple vulnerabilities within Monta's electric vehicle (EV) charging station management software, monta.app. These flaws, if exploited, could grant attackers unauthorized administrative control over charging stations or lead to the disruption of essential charging services.
The vulnerabilities span several critical areas, including missing authentication on WebSocket endpoints (CVE-2026-95102), insufficient rate limiting on authentication requests (CVE-2026-97363), predictable session identifiers (CVE-2026-97212), and publicly accessible charging station identifiers (CVE-2026-93474). The most severe, CVE-2026-95102, carries a CVSS score of 9.4 (Critical) and allows attackers to impersonate charging stations due to a lack of authentication on WebSocket endpoints, potentially leading to privilege escalation and system compromise.
CVE-2026-97363, rated High with a CVSS score of 9.3, addresses the insufficient rate limiting on authentication requests. This weakness could enable attackers to conduct denial-of-service (DoS) attacks or brute-force attempts to gain unauthorized access to the system. The exploitation of this vulnerability could disrupt the availability of charging services, impacting users and operators alike.
Further complicating the security posture, CVE-2026-97212 (CVSS 7.3 High) highlights issues with session management, where predictable session identifiers could allow unauthorized users to authenticate as others or lead to DoS conditions. Additionally, CVE-2026-93474 exposes charging station authentication identifiers, making them publicly accessible and potentially aiding attackers in identifying targets.
Monta, headquartered in the Netherlands, has acknowledged these issues and is actively working on remediation. The company is increasing the adoption of authenticated connections across its network and plans to deprecate unauthenticated access. They also recommend and support the use of OCPP 1.6 Security Profile 2, which includes HTTP Basic Authentication with TLS, for operators to enhance security.
In terms of mitigation, Monta has implemented rate limiting and automated connection throttling at the WebSocket layer to block connections exhibiting abusive patterns, such as rapid reconnections or excessive command volumes. They also ensure that new authenticated connections supersede existing sessions for the same station ID, adhering to the OCPP specification.
The affected software, monta.app, is deployed globally across critical infrastructure sectors, including energy and transportation systems. The broad deployment of this software underscores the potential impact of these vulnerabilities on the wider EV charging ecosystem and the critical infrastructure it supports.
CISA has urged users and administrators to review the advisory and apply any available mitigations or updates as recommended by Monta. The agency also flagged that all versions of monta.app are affected by these vulnerabilities, emphasizing the widespread risk.