Description
Previously, there was no throttling on repeated authentication attempts
to the charging station backend, which could allow an attacker to
execute a denial-of-service attack.
Published: 2026-07-10
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is the absence of throttling on repeated authentication attempts to Hydro‑Québec’s Le Circuit Electrique charging station backend, allowing an attacker to consume resources and trigger a denial‑of‑service, consistent with the identified CWE‑307.

Affected Systems

It affects Hydro‑Québec’s Le Circuit Electrique charging station backend. Specific firmware or hardware revisions are not disclosed, but Hydro‑Québec has released updates for most stations that disable OCPP or add authentication safeguards.

Risk and Exploitability

The CVSS score is 8.7, the EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The lack of throttling permits repeated authentication attempts over the OCPP interface or another network channel, potentially exhausting backend resources. Hydro‑Québec’s official solution—disabling OCPP or implementing authentication controls—removes the main exploitation path.

Generated by OpenCVE AI on August 3, 2026 at 03:56 UTC.

Remediation

Vendor Solution

Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions.


OpenCVE Recommended Actions

  • Install Hydro‑Québec–issued firmware updates that disable OCPP or add authentication safeguards to the charging stations.
  • If stations have not been updated, contact Hydro‑Québec for guidance and consider applying temporary network controls such as firewall restrictions or IP whitelisting to block repeated authentication attempts.
  • Monitor authentication traffic for rapid repeat attempts and configure alerts to detect possible brute‑force or denial‑of‑service attempts.

Generated by OpenCVE AI on August 3, 2026 at 03:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Hydro-québec
Hydro-québec le Circuit Electrique Charging Station Backend
Vendors & Products Hydro-québec
Hydro-québec le Circuit Electrique Charging Station Backend

Fri, 10 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.
Title Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hydro-québec Le Circuit Electrique Charging Station Backend
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-14T14:34:24.114Z

Reserved: 2026-05-07T16:55:26.126Z

Link: CVE-2026-42952

cve-icon Vulnrichment

Updated: 2026-07-14T14:01:12.799Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T23:16:48.203

Modified: 2026-07-14T15:17:01.710

Link: CVE-2026-42952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:00:13Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts