Four Monta Platform Flaws Put Charging-Station Access and Availability at Risk
CISA warns four Monta monta.app flaws (CVSS 9.4) allow station impersonation, credential exposure, DoS and unauthorized charging control.
Illustrative image generated with AI
CISA identifies four vulnerabilities in Monta monta.app
Four vulnerabilities in Monta monta.app could let attackers impersonate charging stations, access sensitive data, perform unauthorized actions or disrupt charging services, according to a CISA advisory published on October 1, 2026.
The advisory, ICSA-26-274-02, lists Monta monta.app: vers:all/* as known_affected. CISA gives the vulnerabilities an overall CVSS v3 score of 9.4. The individual CVEs range from Medium to Critical, depending on the vulnerability and scoring version.
CISA places the product in the Energy and Transportation Systems sectors and reports deployments worldwide. Monta is headquartered in the Netherlands.
An anonymous researcher reported the flaws to CISA. At the time of the advisory, the agency said it had received no reports of known public exploitation specifically targeting these vulnerabilities.
Missing WebSocket authentication carries the highest score
CVE-2026-95102 concerns WebSocket endpoints that do not properly authenticate connections. CISA says an attacker could impersonate a charging station, access sensitive information or take unauthorized actions. Because the affected function does not require authentication, the weakness could also enable privilege escalation and potentially compromise the wider system.
CISA classifies the issue as CWE-306 — Missing Authentication for Critical Function. It is rated 9.4 Critical under CVSS 3.1 and 9.3 Critical under CVSS 4.0. Its vectors are:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
The CVE Program record for CVE-2026-95102 is displayed as RESERVED, with details to be added by the assigning CNA. CISA’s advisory provides the technical description, affected product, CWE and severity information.
Authentication flooding and session handling create separate risks
CVE-2026-97363 affects the WebSocket API, which does not limit the number of authentication requests. CISA says this could enable denial-of-service attacks or brute-force attempts intended to obtain unauthorized access.
The flaw is CWE-307 — Improper Restriction of Excessive Authentication Attempts. Its ratings are 7.5 High under CVSS 3.1 and 8.7 High under CVSS 4.0:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
The CVE Program page for CVE-2026-97363 showed a loading message in the supplied record. CISA’s advisory contains the available technical and severity details.
A different weakness, CVE-2026-97212, involves how the WebSocket backend associates sessions with charging-station identifiers. CISA says those identifiers are predictable and that multiple endpoints can connect using the same session identifier. This could let an unauthorized user authenticate as someone else, or allow denial of service by flooding the backend with valid session requests.
CISA assigns this flaw CWE-613 — Insufficient Session Expiration. It scores 7.3 High under CVSS 3.1 and 6.9 Medium under CVSS 4.0:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
These are distinct weaknesses and potential effects. The advisory does not say they were combined in an observed attack.
Mapping platforms expose station authentication identifiers
CVE-2026-93474 concerns charging-station authentication identifiers that are publicly accessible through web-based mapping platforms. CISA categorizes it as CWE-522 — Insufficiently Protected Credentials.
The vulnerability has a score of 6.5 Medium under CVSS 3.1 and 6.9 Medium under CVSS 4.0:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CISA’s summary warns of possible unauthorized administrative control over vulnerable charging stations or disruption of charging services through denial of service. The advisory describes the vulnerabilities separately; it does not report that they formed a single attack chain.
Monta describes authentication and connection controls
Monta told CISA it is expanding authenticated connections across its network and phasing out unauthenticated access on a rolling basis. The company supports OCPP 1.6 Security Profile 2, which uses HTTP Basic Authentication over TLS, and encourages operators to enable it.
Monta also says it has deployed WebSocket-layer rate limiting and automated connection throttling. According to the company, its platform identifies and blocks abusive patterns such as rapid reconnections, station-ID brute-forcing and excessive command volume.
For duplicate connection attempts, Monta says its platform follows the OCPP specification: a new authenticated connection replaces an existing session for the same station ID. These are measures reported by the company, not confirmation that a fixed software version is available.
CISA lists all versions, vers:all/*, as affected. The advisory does not specify a fixed version or patch.
CISA advises reducing exposure and assessing changes
CISA recommends limiting network exposure for control-system devices and keeping control networks and remote devices behind firewalls, separated from business networks. When remote access is necessary, it advises using more secure methods such as VPNs. CISA also cautions that VPNs may contain vulnerabilities, should be kept current and are only as secure as the devices connected through them.
Before deploying defensive measures, CISA says organizations should conduct an impact analysis and risk assessment. For suspected malicious activity, it advises following established internal procedures and reporting findings to CISA for tracking and correlation.
Monta’s descriptions of the behaviors its controls detect may help operators focus on WebSocket connection activity, including rapid reconnections, station-ID brute-forcing patterns and excessive command volume. The advisory does not provide literal indicators such as IP addresses, domains or file hashes.
CISA also directs readers to its ICS security practices and defense-in-depth guidance. Its recommended reading includes technical paper ICS-TIP-12-146-01B, titled Targeted Cyber Intrusion Detection and Mitigation Strategies.
Sources
This article is an original reworking based on the sources below.
- primary sourceCVE Program
- primary sourceCVE Program
- CISA Advisories




