Description
The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation.
Published: 2026-07-10
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hydro‑Québec’s Le Circuit Electrique charging station backend contains a websocket endpoint that accepts connections without any authentication, creating an improper access control flaw. An attacker who can reach this endpoint can obtain privileged access to the backend system, potentially manipulating charging station functions or securing further exploitation of the station’s control plane.

Affected Systems

The vulnerability applies to the backend service of Hydro‑Québec Le Circuit Electrique charging stations. No specific version information is provided in the advisory, but the issue affects all instances that expose the unauthenticated websocket interface.

Risk and Exploitability

Hydro‑Québec classifies the flaw as critical, reflected by a CVSS score of 9.3. The low EPSS score of less than 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw remotely by connecting to the unprotected websocket, bypassing normal authentication procedures. Hydro‑Québec’s mitigation—disabling OCPP on most stations and adding authentication for those still using OCPP—reduces the attack surface.

Generated by OpenCVE AI on July 29, 2026 at 09:36 UTC.

Remediation

Vendor Solution

Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions.


OpenCVE Recommended Actions

  • Apply Hydro‑Québec’s firmware update that disables OCPP on affected stations that remain on OCPP.
  • For stations that continue to use OCPP and have not received the update, restrict access to the backend by applying network segmentation or firewall rules to allow connections only from trusted management systems.
  • Continuously monitor the websocket endpoint for unauthorized connection attempts to ensure no unauthenticated traffic reaches the backend.

Generated by OpenCVE AI on July 29, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Hydro-québec
Hydro-québec le Circuit Electrique Charging Station Backend
Vendors & Products Hydro-québec
Hydro-québec le Circuit Electrique Charging Station Backend

Fri, 10 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.
Title Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hydro-québec Le Circuit Electrique Charging Station Backend
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-14T14:34:32.306Z

Reserved: 2026-01-27T23:33:47.834Z

Link: CVE-2026-20744

cve-icon Vulnrichment

Updated: 2026-07-14T14:00:05.479Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:45:04Z

Weaknesses