Junglewise Threat Intelligence

CVE-2026-50176: EVoke Systems EVoke CSMS improper rate limiting in WebSocket API

CVE-2026-50176 · Severity: high · CVSS 7.5 · Published 2026-06-25

Technologies: EVoke Systems CSMS. Vendors: EVoke Systems.

Executive brief

EVoke Systems Charging Station Management System (CSMS), a platform used to manage electric vehicle charging infrastructure, is vulnerable to attacks that could disrupt service. Because the system does not limit the number of login attempts, an attacker could overwhelm the service or attempt to guess credentials. This could lead to a denial-of-service, preventing drivers from using charging stations, or potentially allow unauthorized access to the management platform.

Technical details

The WebSocket API in EVoke CSMS fails to implement proper rate limiting or restrictions on the frequency of authentication requests (CWE-307). This vulnerability allows a remote, unauthenticated attacker to perform high-frequency connection attempts. Exploitation can result in a denial-of-service (DoS) condition by exhausting system resources or facilitate brute-force attacks to bypass authentication. The vendor is addressing this by implementing connection rate limiting at the WebSocket gateway layer and migrating legacy devices to more secure OCPP profiles (Security Profile 2 or 3).

Affected products

  • EVoke Systems EVoke CSMS (Charging Station Management System) All versions

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory: CISA ICSA-26-176-02 published

References

Related threats