Description
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Apply Workaround
AI Analysis

Impact

The vulnerability arises from predictable WebSocket session identifiers that allow multiple connections to claim the same charging station identifier. This allows an attacker to impersonate another station and gain unauthorized access, or to flood the backend with legitimate-looking session requests that crash or degrade service. The weakness is a form of insufficient session expiration and management, identified as CWE‑613.

Affected Systems

The affected product is Monta’s monta.app platform, which manages charging station sessions via WebSocket on an OCPP 1.6 network. No specific version information is supplied; the issue applies to all installations that use the current backend session handling as described.

Risk and Exploitability

The CVSS score of 6.9 classifies this as a moderate severity vulnerability. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating limited evidence of widespread exploitation. The most likely attack vector is over the network, where an adversary can open multiple WebSocket connections using the same station identifier. The vendor’s workaround includes adopting authenticated (HTTP Basic Auth over TLS) sessions, rate limiting, and automated throttling of abusive connection patterns. Without these controls, an attacker could achieve unauthorized access or a denial‑of‑service condition.

Generated by OpenCVE AI on October 2, 2026 at 22:51 UTC.

Remediation

Vendor Workaround

Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.


OpenCVE Recommended Actions

  • Enable OCPP 1.6 Security Profile 2 by configuring HTTP Basic Authentication over TLS on all station connections.
  • Deploy rate limiting and automated connection throttling on the WebSocket layer to block rapid reconnection attempts and brute‑force patterns.
  • Disable unauthenticated access and enforce that a new authenticated connection supersedes any existing session for the same station ID.

Generated by OpenCVE AI on October 2, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Title Monta monta.app Insufficient Session Expiration
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-02T21:30:37.104Z

Reserved: 2026-09-24T16:22:04.112Z

Link: CVE-2026-97212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T22:16:56.760

Modified: 2026-10-02T22:16:56.760

Link: CVE-2026-97212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:00:16Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration