A cloud platform that runs electric vehicle chargers has been accepting connections from charging stations without checking who they really are, according to a CISA advisory published October 1. CISA says four flaws in Monta's monta.app platform could let attackers gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Monta is headquartered in the Netherlands and its platform is deployed worldwide, according to the advisory, which lists the energy and transportation systems sectors. CISA marks every version of monta.app as affected. An anonymous researcher reported the bugs, and CISA says no known public exploitation of them has been reported to it so far.
A charger's ID was close to a password
Chargers talk to back-end platforms like Monta's over WebSocket connections, a long-lived two-way channel between device and server. The most serious bug, CVE-2026-95102 (CVSS v3 9.4), is missing authentication on those WebSocket endpoints. CISA says that lets attackers impersonate charging stations and gain unauthorized access to sensitive data or perform unauthorized actions.
The other three, in order of severity:
- CVE-2026-97363 (CVSS 7.5): no limit on the number of authentication requests to the WebSocket API, which may allow brute-forcing or denial of service.
- CVE-2026-97212 (CVSS 7.3): the back end uses charging station identifiers to associate sessions but lets multiple endpoints connect with the same one, resulting in predictable session identifiers. CISA says this may let unauthorized users authenticate as others or let an attacker overwhelm the back end.
- CVE-2026-93474 (CVSS 6.5): charging station authentication identifiers are publicly accessible through web-based mapping platforms.
Read together, the advisory describes a system where the value that identifies a charger could be found in public, with nothing originally in place to stop repeated guessing against the API.
Operators should enable OCPP Security Profile 2
There is no version to upgrade to. The remediation sits partly with Monta and partly with the operators who connect chargers to it. Monta told CISA it supports OCPP 1.6 Security Profile 2, which adds HTTP Basic Authentication over TLS to the charger connection, and it encourages operators to enable it. The company says it is working to increase adoption of authenticated connections across its network and to deprecate unauthenticated access on a rolling basis.
Monta also says it has implemented rate limiting and automated connection throttling at the WebSocket layer, automatically blocking connections that show rapid reconnection, ID brute-forcing or excessive command volume. And it says its platform follows the OCPP specification on duplicate connections, so a new authenticated connection supersedes an existing session for the same station ID.
CISA's standing advice for control systems applies too: keep devices off the open internet, place them behind firewalls and isolate them from business networks, and use secured remote access only where it is genuinely needed.
Charging back ends keep failing the same test
This is not the first charging management platform found trusting whatever connects to it. In June, IntelFusions reported critical flaws that let attackers hijack EV charging networks run on another platform. As chargers multiply in car parks and along highways, the cloud services behind them are becoming energy infrastructure in their own right, and an identifier that anyone can look up on a public map was never going to work as a credential.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.