Impact
The vulnerability arises from predictable WebSocket session identifiers that allow multiple connections to claim the same charging station identifier. This allows an attacker to impersonate another station and gain unauthorized access, or to flood the backend with legitimate-looking session requests that crash or degrade service. The weakness is a form of insufficient session expiration and management, identified as CWE‑613.
Affected Systems
The affected product is Monta’s monta.app platform, which manages charging station sessions via WebSocket on an OCPP 1.6 network. No specific version information is supplied; the issue applies to all installations that use the current backend session handling as described.
Risk and Exploitability
The CVSS score of 6.9 classifies this as a moderate severity vulnerability. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating limited evidence of widespread exploitation. The most likely attack vector is over the network, where an adversary can open multiple WebSocket connections using the same station identifier. The vendor’s workaround includes adopting authenticated (HTTP Basic Auth over TLS) sessions, rate limiting, and automated throttling of abusive connection patterns. Without these controls, an attacker could achieve unauthorized access or a denial‑of‑service condition.
OpenCVE Enrichment