TL;DR
CISA published an advisory warning operators about several Monta EV charging vulnerabilities. Specifically, these flaws allow unauthenticated actors to hijack charging hardware or disrupt service. Administrators should immediately enforce authenticated connections and enable rate limiting across their charging networks.
- Vulnerabilities: 4 flaws (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
- Highest severity: 9.4 (Critical · CVSSv3)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-95102 | 9.4 | CWE-306 | Not exploited |
| CVE-2026-97363 | 7.5 | CWE-307 | Not exploited |
| CVE-2026-97212 | 7.3 | CWE-613 | Not exploited |
| CVE-2026-93474 | 6.5 | CWE-522 | Not exploited |
CISA KEV isn't the only exploit signal. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy It Matters
Monta powers charging networks across the transportation and energy sectors worldwide. Therefore, security defects in its cloud platform threaten public and private transit. According to CISA, “Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.” Industry estimates indicate that thousands of commercial chargers rely on Monta software. Consequently, unresolved bugs could allow rogue actors to manipulate power delivery or access private customer data. Resolving these Monta EV charging vulnerabilities is essential to protect critical transit systems.
How The Attack Works
The issues stem from weak authentication and poor session handling within WebSocket endpoints. First, the primary flaw lacks authentication checks entirely. As CISA notes, “WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations.” Next, attackers can find station identifiers on public web maps. Threat actors then use these identifiers to open unauthorized WebSocket connections. Furthermore, the API permits unlimited authentication attempts without rate limits. Finally, the backend allows multiple endpoints to share identical session identifiers, enabling session hijacking.
Exploitation Status
CISA confirmed that threat actors have not exploited these flaws publicly. The advisory states, “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” In addition, researchers have not released public exploit code.
Affected Versions
The vulnerabilities affect all versions of the Monta monta.app platform prior to recent backend remediations.
Patch And Mitigation Steps
Monta deployed automated rate limiting to block abusive WebSocket connections. Furthermore, operators must enable OCPP 1.6 Security Profile 2 to require authentication over TLS. Network administrators should also isolate control systems behind firewalls. Finally, operators can review the full guidance in the official CISA ICS advisory.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!