CVE-2026-97212High· 7.3▾ TwilightThe WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulne…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97363High· 7.5The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
CVE-2026-95102Critical· 9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations
CVE-2026-93474Medium· 6.5Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-104468Medium· 4.8YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps
CVE-2022-50692High· 7.5SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability
CVE-2026-66253Low· 3.1iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of …