Description
Previously, there was no throttling on repeated authentication attempts
to the charging station backend, which could allow an attacker to
execute a denial-of-service attack.
Published: 2026-07-10
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is the absence of throttling for repeated authentication exhaust backend resources and trigger a denial‑of‑service. The flaw is identified as CWE‑307.

Affected Systems

The affected system comprises Hydro‑Québec’s Le Circuit Electrique charging station backend. Specific firmware versions are not disclosed; the issue was observed on stations prior to Hydro‑Québec’s recent updates that disabled OCPP. The backend lacks throttling for repeated authentication attempts, permitting an attacker to exhaust system resources flaw is identified as CWE‑307 and means a successful adversary could render the station inoperable, disrupting charging services and potentially affecting many users.

Risk and Exploitability

The CVSS score of 8.7. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an adversary sending repeated authentication requests over the OCPP connection or a similar network channel to the backend, exhausting resources and triggering a denial‑of‑service. The patch implemented by Hydro‑Québec—disabling OCPP or adding authentication safeguards—removes the primary exploitation path.

Generated by OpenCVE AI on July 29, 2026 at 09:36 UTC.

Remediation

Vendor Solution

Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions.


OpenCVE Recommended Actions

  • Apply Hydro‑Québec’s firmware update that disables OCPP or implements authentication safeguards to the charging stations.
  • If stations remain on older firmware, contact Hydro‑Québec for guidance and, if necessary, deploy temporary network controls such as firewall restrictions or IP whitelisting to limit repeated authentication attempts.
  • Enable monitoring of authentication traffic and set alerts for rapid repeat attempts to detect potential brute‑force attempts.

Generated by OpenCVE AI on July 29, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Hydro-québec
Hydro-québec le Circuit Electrique Charging Station Backend
Vendors & Products Hydro-québec
Hydro-québec le Circuit Electrique Charging Station Backend

Fri, 10 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.
Title Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hydro-québec Le Circuit Electrique Charging Station Backend
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-14T14:34:24.114Z

Reserved: 2026-05-07T16:55:26.126Z

Link: CVE-2026-42952

cve-icon Vulnrichment

Updated: 2026-07-14T14:01:12.799Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:45:04Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts