securityonline.info 2 Oct 2026, 01:55 UTC

CISA Warns Monta EV Chargers Face Unauthorised Control Risks

CISA Warns Monta EV Chargers Face Unauthorised Control Risks

CISA has issued an advisory warning that Monta EV charging networks may be exposed to unauthenticated access due to multiple vulnerabilities in the Monta monta[.]app platform. The four flaws—CVE-2026-95102, CVE-2026-97363, CVE-2026-97212 and CVE-2026-93474—are described as high-severity issues with CVSSv3 scores up to 9.4. The advisory notes that successful exploitation could allow unauthorised administrative control over vulnerable charging stations or disrupt services via denial-of-service attacks.

At the time of the report, there was no confirmed public exploitation, and there has been no released public exploit code. The article emphasises that thousands of commercial chargers rely on Monta software, underlining the potential impact if these bugs remain unpatched.

The vulnerabilities stem from weak authentication and poor session handling in WebSocket endpoints. Specifically, WebSocket connections can be impersonated due to missing authentication checks, and station identifiers from public maps can be used to open unauthorised connections. The API reportedly allows unlimited authentication attempts, and identical session identifiers may be reused across endpoints, enabling session hijacking.

Monta has deployed automated rate limiting to curb abusive WebSocket connections, and the guidance calls for enabling OCPP 1.6 Security Profile 2 to require authentication over TLS, along with network segmentation to protect control systems. Operators are urged to consult the official CISA ICS advisory for full mitigation steps. The report states there is no known exploitation reported to CISA to date.

View full article

Article by CyberSIXT