The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-274-02 warning of a cascade of serious vulnerabilities in the Monta electric vehicle (EV) charging ecosystem and mobile management platform (monta.app). The weaknesses span missing WebSocket authentication (CVE-2026-95102), session collision and predictable tokens (CVE-2026-97212), and unthrottled API endpoints (CVE-2026-97363), enabling remote threat actors to impersonate hardware charging stations, hijack active charging sessions, and initiate coordinated denial-of-service disruptions against municipal and enterprise charging grids.
The Expanding Threat Surface of EV Smart Grid Infrastructure
Modern commercial EV charging networks rely on the Open Charge Point Protocol (OCPP), typically transported over WebSockets (ws:// or wss://), to exchange telemetry, billing events, smart metering, and electrical load balancing commands between physical Charging Station Management Systems (CSMS) and charging kiosks.
Monta's platform powers tens of thousands of commercial, fleet, and residential charging stations across Europe and North America. Because high-power Level 3 DC fast chargers draw significant megawatts from local distribution grids, tampering with fleet charging parameters can cause localized transformer overloads, power brownouts, and fraudulent billing siphoning.
Root Cause Breakdown: The WebSocket Authentication Collapse
Security audits uncovered that Monta's cloud OCPP gateway failed to enforce cryptographic authentication when field charging kiosks established WebSocket connections:
1. Unauthenticated Station Impersonation (CVE-2026-95102)
When an EV charger establishes an OCPP WebSocket connection to the cloud CSMS, it initiates an HTTP Upgrade request:
GET /ocpp/CP-994821 HTTP/1.1
Host: ws.monta.app
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
Sec-WebSocket-Protocol: ocpp1.6
Under standard OCPP Security Profile 2 or 3, the charger must provide HTTP Basic Authentication with a secret per-device password or present a client TLS certificate (mTLS). In Monta's vulnerable deployment, the gateway accepted the WebSocket connection and immediately recognized the client as CP-994821 solely based on the URI path, without validating credentials or requiring cryptographic handshakes.
2. Session Prediction and Multiplexing Collision (CVE-2026-97212)
Because session identifiers were directly derived from the public station identifier, multiple client connections specifying the same charger ID were multiplexed into the same internal session context. An attacker connecting from anywhere on the internet could overwrite the socket state of a physical charger, severing the actual charger's connection and receiving incoming telemetry:
// Attacker intercepting OCPP meter values:
[
2,
"msg_8849201",
"MeterValues",
{
"connectorId": 1,
"transactionId": 48102,
"meterValue": [
{
"timestamp": "2026-10-01T21:45:00Z",
"sampledValue": [
{ "value": "48.2", "unit": "kWh", "measurand": "Energy.Active.Import.Register" }
]
}
]
}
]
3. Public Charger ID Enumeration (CVE-2026-93474 & CVE-2026-97363)
Making exploitation trivial, charging station hardware identifiers were exposed in plaintext in public web-based locator maps (CVE-2026-93474). Coupled with a total lack of API rate-limiting (CVE-2026-97363), an adversary could programmatically scrape thousands of station IDs and initiate automated brute-force disconnect commands or broadcast fake transaction stops across entire metropolitan areas.
| Vulnerability ID | CWE Classification | Attack Vector | Operational Impact |
|---|---|---|---|
| CVE-2026-95102 | CWE-306 Missing Authentication | Remote / WebSocket API | Rogue charging station impersonation |
| CVE-2026-97212 | CWE-384 Session Fixation / Prediction | Remote / Predictable IDs | Hijacking legitimate customer charging sessions |
| CVE-2026-97363 | CWE-799 Improper Rate Limiting | Remote / API Flooding | Distributed denial of charging grid services |
| CVE-2026-93474 | CWE-200 Information Disclosure | Public Web Map Metadata | Global discovery of target charge point IDs |
Defensive Remediation Guidelines for EV Fleet Operators
- Enforce OCPP Security Profile 2 / 3: Transition all charger connections from unauthenticated WebSockets to WSS with individual per-charger basic authentication keys or client-side X.509 certificates (mTLS).
- Implement Strict WebSocket Rate Limiting: Deploy an API gateway (e.g., Envoy or Kong) configured with token-bucket rate limiting on all WebSocket upgrade endpoints to throttle connection attempts.
- Apply Cloud Platform Updates: Monta has deployed backend fixes across their cloud CSMS infrastructure. Operators should verify in their administrative dashboards that all connected charging hardware is registered under strict authentication enforcement modes.



