Impact
The vulnerability allows an attacker to obtain charging station identifiers and potentially credentials because they are publicly accessible through web‐based mapping platforms; this exposure enables unauthorized access to station management functions and is a classic case of insufficiently protected credentials (CWE‑522).
Affected Systems
The affected product is Monta’s Monta.app platform. No specific version information is available in the advisory, so any deployment of Monta.app remains potentially vulnerable until a dedicated fix is released.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV database. The attack vector is inferred to be remote, as the credentials are exposed over the internet via public web mapping interfaces. Mitigations are limited to the workaround described by Monta, which emphasizes moving to authenticated connections and implementing rate limiting at the WebSocket layer.
OpenCVE Enrichment