Executive brief
The Hydro-Québec Le Circuit Electrique charging station backend, which manages electric vehicle charging infrastructure, is vulnerable to a denial-of-service attack. An attacker can connect multiple malicious clients using the same charging station ID to overwhelm the system. This could lead to service outages, preventing legitimate users from using charging stations or disrupting the management of the charging network.
Technical details
The Hydro-Québec Le Circuit Electrique charging station backend fails to properly restrict concurrent sessions using the same charging station identifier. This vulnerability, classified as Insufficient Session Expiration (CWE-613), allows a remote attacker to deploy multiple instances of malicious Open Charge Point Protocol (OCPP) clients using a single ID. By flooding the backend with these duplicate connections, an attacker can exhaust system resources and cause a denial-of-service (DoS) condition. The vulnerability is reachable over the network without authentication. Hydro-Québec has mitigated the risk by disabling OCPP on most stations and implementing new authentication systems for those still requiring it as of June 2026.
Affected products
- Hydro-Québec Le Circuit Electrique charging station backend before June 2026
Timeline
- 2026-07-07: advisory: Initial publication by CISA (ICSA-26-188-01)
- 2026-07-10: disclosed: CVE-2026-44383 published to NVD
- 2026-06-01: patched: Remediations implemented by Hydro-Québec in June 2026 update