WebSocket endpoints lack proper authentication mechanisms...
Critical severity
Unreviewed
Published
Feb 27, 2026
to the GitHub Advisory Database
•
Updated Feb 27, 2026
Description
Published by the National Vulnerability Database
Feb 27, 2026
Published to the GitHub Advisory Database
Feb 27, 2026
Last updated
Feb 27, 2026
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sent to the backend. An unauthenticated attacker can connect to the
OCPP WebSocket endpoint using a known or discovered charging station
identifier, then issue or receive OCPP commands as a legitimate charger.
Given that no authentication is required, this can lead to privilege
escalation, unauthorized control of charging infrastructure, and
corruption of charging network data reported to the backend.
References