Impact
WebSocket endpoints in Monta’s monta.app platform do not enforce authentication, allowing attackers to impersonate charging stations and issue commands or read sensitive data. This represents a CWE‑306 Missing Authentication flaw that can enable privilege escalation and compromise system integrity.
Affected Systems
The affected product is Monta’s monta.app charging infrastructure, with no specific version information provided in the advisory. Operators should verify which deployments are running the vulnerable component.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, indicating high severity. The EPSS score is not reported, and it is not listed in the CISA KEV catalog. Attackers can exploit it by sending unauthenticated WebSocket requests from any network path that can reach the endpoint; no special privileges or authentication are required, making exploitation trivial for an attacker who can reach the target.
OpenCVE Enrichment