CVE-2026-40702 PUBLISHED

EVoke Systems EVoke CSMS Missing Authentication for Critical Function

Assigner: icscert
Reserved: 18.06.2026 Published: 25.06.2026 Updated: 26.06.2026

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor EVoke
Product EVoke CSMS
Versions Default: unaffected
  • Version All versions is affected

Workarounds

EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible

Solutions

EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.

Credits

  • Khaled Sarieddine and Mohammad Ali Sayed reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-306 CWE