IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Monta monta.app

CRITICAL
CVSS 9.4
Date 2026-10-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.

// Vulnerabilities (4)

CVE ID CVSS Score Severity Description
CVE-2026-97212 7.3 high
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
CVE-2026-97363 7.5 high
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
CVE-2026-93474 6.5 medium
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-95102 9.4 critical
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

// Remediations (3)

Mitigation: Monta states that they have implemented rate limiting and automated connection throttling at the Web
Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked.
Mitigation: Monta states that their platform handles duplicate connection attempts per the OCPP specification, w
Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID.
Mitigation: Monta states that they are actively working to increase adoption of authenticated connections across
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.

// References