Impact
Hydro‑Québec’s Le Circuit Electrique charging station backend contains a websocket endpoint that accepts connections without any authentication, creating an improper access control flaw. An attacker who can reach this endpoint can obtain privileged access to the backend system, potentially manipulating charging station functions or securing further exploitation of the station’s control plane.
Affected Systems
The vulnerability applies to the backend service of Hydro‑Québec Le Circuit Electrique charging stations. No specific version information is provided in the advisory, but the issue affects all instances that expose the unauthenticated websocket interface.
Risk and Exploitability
Hydro‑Québec classifies the flaw as critical, reflected by a CVSS score of 9.3. The low EPSS score of less than 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw remotely by connecting to the unprotected websocket, bypassing normal authentication procedures. Hydro‑Québec’s mitigation—disabling OCPP on most stations and adding authentication for those still using OCPP—reduces the attack surface.
OpenCVE Enrichment