Tech
Monta EV charging flaws: chargers can be impersonated (CVSS 9.4)
TL;DR: CISA advisory ICSA-26-274-02 (October 1, 2026) lists four vulnerabilities in all versions of the Monta EV charging platform (monta.app), the worst rated CVSS 9.4. The OCPP WebSocket endpoints do not authenticate charging stations, and station IDs are publicly visible. Anyone operating chargers through Monta should enable OCPP 1.6 Security Profile 2 (Basic Auth over TLS) with a unique password per station as soon as possible.
What CISA published
CVE
Weakness
C...
Read the full discussion on Dev.to
This article was aggregated from Dev.to. Click to join the conversation.
View on Dev.to