Junglewise Threat Intelligence

CVE-2026-44622: EVoke Systems EVoke CSMS credential exposure via mapping platforms

CVE-2026-44622 · Severity: medium · CVSS 6.5 · Published 2026-06-25

Technologies: EVoke Systems CSMS. Vendors: EVoke Systems.

Executive brief

EVoke Systems Charging Station Management System (CSMS) is used to manage and monitor electric vehicle charging infrastructure. A vulnerability exists where authentication identifiers for charging stations are publicly accessible through web-based mapping platforms. This exposure could allow unauthorized individuals to identify and potentially spoof charging stations, leading to unauthorized administrative control or disruption of charging services.

Technical details

The EVoke Systems Charging Station Management System (CSMS) suffers from a credential exposure vulnerability (CWE-522) where charging station authentication identifiers are accessible via public web-based mapping platforms. This vulnerability stems from the system's support for legacy OCPP security profiles (0 and 1) in certain hardware, which lack robust authentication. An unauthenticated remote attacker can harvest these identifiers to impersonate legitimate charging stations. Successful exploitation can lead to unauthorized administrative actions or denial-of-service by disrupting legitimate station connections. The vendor is working to migrate devices to OCPP Security Profiles 2 or 3 and implementing server-side allow-listing to mitigate risks for legacy hardware.

Affected products

  • EVoke Systems EVoke CSMS All versions

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory: CISA Advisory ICSA-26-176-02 published

References

Related threats