Executive brief
EVoke Systems Charging Station Management System (CSMS) is used to manage and monitor electric vehicle charging infrastructure. A vulnerability exists where authentication identifiers for charging stations are publicly accessible through web-based mapping platforms. This exposure could allow unauthorized individuals to identify and potentially spoof charging stations, leading to unauthorized administrative control or disruption of charging services.
Technical details
The EVoke Systems Charging Station Management System (CSMS) suffers from a credential exposure vulnerability (CWE-522) where charging station authentication identifiers are accessible via public web-based mapping platforms. This vulnerability stems from the system's support for legacy OCPP security profiles (0 and 1) in certain hardware, which lack robust authentication. An unauthenticated remote attacker can harvest these identifiers to impersonate legitimate charging stations. Successful exploitation can lead to unauthorized administrative actions or denial-of-service by disrupting legitimate station connections. The vendor is working to migrate devices to OCPP Security Profiles 2 or 3 and implementing server-side allow-listing to mitigate risks for legacy hardware.
Affected products
- EVoke Systems EVoke CSMS All versions
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory: CISA Advisory ICSA-26-176-02 published