VORANT. Threat Intelligence Research Sign in Create a free account

Monta EV charging platform has unauth flaws

routine vulnerability energytransportation

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CISA warns four vulnerabilities in Monta's EV charging platform let attackers impersonate stations, hijack sessions, or disrupt charging via unauthenticated WebSocket connections.

CISA published an ICS advisory covering four vulnerabilities in Monta's monta.app platform, a cloud-based EV charging management system deployed worldwide (vendor headquartered in the Netherlands), affecting the Energy and Transportation Systems sectors. The core issue (CVE-2026-95102, CWE-306) is that WebSocket endpoints used by charging stations to communicate with the backend lack proper authentication, allowing an attacker to impersonate a station, access sensitive data, or perform unauthorized actions potentially leading to privilege escalation over the system. Related flaws compound the risk: the WebSocket API has no rate limiting on authentication attempts (CVE-2026-97363, CWE-307), enabling brute-force or DoS attacks; the backend accepts multiple connections using the same predictable session identifier (CVE-2026-97212, CWE-613), allowing session hijacking or backend overload; and charging station authentication identifiers are exposed via public web-mapping platforms (CVE-2026-93474, CWE-522), making credential harvesting trivial for an attacker who can locate a target station.

Chained together, these issues could let an attacker take administrative control of charging stations or knock them offline through denial-of-service. CISA states there is no known public exploitation of these vulnerabilities at this time. Monta has responded with several mitigations rather than patches: rolling deprecation of unauthenticated connections in favor of OCPP 1.6 Security Profile 2 (HTTP Basic Auth over TLS), WebSocket-layer rate limiting and connection throttling to detect abusive reconnection/brute-force patterns, and enforcement of the OCPP spec so a new authenticated session supersedes an existing one for the same station ID.

Defenders operating Monta-connected charging infrastructure should prioritize enabling OCPP 1.6 Security Profile 2 where supported, verify their stations are not relying on legacy unauthenticated WebSocket connections, and apply standard ICS network segmentation: minimize internet exposure of control-system devices, place them behind firewalls, and use VPNs for any required remote access. Given the lack of mandatory patching (remediation is vendor-side and rolling) and the critical-infrastructure nature of EV charging networks, operators should monitor for anomalous connection patterns and engage with Monta regarding migration timelines to authenticated profiles.

Mentioned in this report

Vulnerabilities CVE-2026-93474CVE-2026-95102CVE-2026-97212CVE-2026-97363

Detection guidance

Failed Authentication Against OCPP WebSocket Endpoint

ATT&CK T1110

HTTP 401/403 responses on OCPP WebSocket upgrade requests; a high rate from one source suggests brute-forcing of charge-point credentials. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Failed Authentication Against OCPP WebSocket Endpoint
id: 466f1373-2bc7-57bf-abd4-0eb6312b266b
status: experimental
description: Detects rejected (401/403) requests to OCPP WebSocket endpoints used
  by EV charging stations. Individually these are common misconfigurations, but alert
  on a high rate of them from one source IP or against many station IDs within a short
  window (threshold to be applied in the SIEM, for example 20 or more in 5 minutes).
  This pattern indicates brute-forcing or credential stuffing of station identifiers,
  as enabled by missing rate limiting on WebSocket authentication.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02
tags:
- attack.credential-access
- attack.t1110
- attack.impact
- attack.t1499
logsource:
  category: webserver
detection:
  selection:
    cs-method: GET
    cs-uri-stem|contains: /ocpp
    sc-status:
    - 401
    - 403
  condition: selection
fields:
- c-ip
- cs-uri-stem
- sc-status
- cs-User-Agent
falsepositives:
- Newly deployed or misconfigured charging stations retrying with wrong credentials
- Station credential rotation causing temporary rejected reconnects
level: low
author: Vorant

Unauthenticated OCPP WebSocket Session Established

ATT&CK T1078

Successful WebSocket upgrade (101) on an OCPP endpoint with no authenticated user, indicating a legacy or impersonated station connection. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Unauthenticated OCPP WebSocket Session Established
id: 29a955dc-e4f8-52f6-9238-9e5fd53c0045
status: experimental
description: Detects successful WebSocket upgrades (HTTP 101) on OCPP endpoints where
  no authenticated username was logged. This indicates a station connected using legacy
  unauthenticated mode (no Security Profile 2 Basic Auth), which an attacker could
  abuse to impersonate a charging station.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02
tags:
- attack.initial-access
- attack.t1078
- attack.reconnaissance
- attack.t1590
logsource:
  category: webserver
detection:
  selection:
    cs-method: GET
    cs-uri-stem|contains: /ocpp
    sc-status: 101
    cs-username: '-'
  condition: selection
fields:
- c-ip
- cs-uri-stem
- cs-User-Agent
falsepositives:
- Legitimate legacy charging stations that have not yet migrated to OCPP 1.6 Security
  Profile 2
- Test or staging stations connecting without credentials
level: medium
author: Vorant

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,566 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs