VORANT. Threat Intelligence Sign in Get the full feed

EVoke charging stations lack authentication, enable DoS

high vulnerability energytransportation

CISA warns that all versions of EVoke CSMS have critical authentication flaws allowing attackers to impersonate charging stations, access sensitive data, and launch denial-of-service attacks.

CISA has disclosed four vulnerabilities in EVoke Systems' Charging Station Management System (CSMS) affecting all deployed versions worldwide. The most severe flaw (CVE-2026-40702) stems from WebSocket endpoints lacking proper authentication, enabling attackers to impersonate legitimate charging stations and gain unauthorized administrative control. Additional vulnerabilities include absence of rate limiting on authentication attempts (CVE-2026-50176), predictable session identifiers allowing duplicate connections (CVE-2026-54479), and publicly accessible charging station credentials via web mapping platforms (CVE-2026-44622).

The root cause traces to EVoke's hardware-agnostic platform design, which supports multiple charger OEMs with varying OCPP security profiles. Many legacy chargers in the field support only Security Profile 0 or 1, lacking modern authentication mechanisms. EVoke is working with OEM partners to migrate devices to Security Profile 2 or 3 where possible, but acknowledges some legacy hardware from defunct manufacturers cannot be upgraded. The vendor is implementing server-side compensating controls including allowlisting registered charger IDs, enforcing single connections per device, anomaly monitoring, and rate limiting.

The vulnerabilities affect critical infrastructure in both the Energy and Transportation sectors. While no active exploitation has been reported to CISA, successful attacks could disrupt electric vehicle charging services or provide unauthorized access to charging network management systems. Organizations operating EVoke CSMS should contact the vendor for remediation guidance, implement network segmentation, and restrict internet exposure of charging station management systems.

Mentioned in this report

Vulnerabilities CVE-2026-40702CVE-2026-44622CVE-2026-50176CVE-2026-54479

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free