Executive brief
EVoke Systems Charging Station Management System (CSMS), a platform used to manage electric vehicle charging infrastructure, is vulnerable to attacks that could disrupt service. Because the system does not limit the number of login attempts, an attacker could overwhelm the service or attempt to guess credentials. This could lead to a denial-of-service, preventing drivers from using charging stations, or potentially allow unauthorized access to the management platform.
Technical details
The WebSocket API in EVoke CSMS fails to implement proper rate limiting or restrictions on the frequency of authentication requests (CWE-307). This vulnerability allows a remote, unauthenticated attacker to perform high-frequency connection attempts. Exploitation can result in a denial-of-service (DoS) condition by exhausting system resources or facilitate brute-force attacks to bypass authentication. The vendor is addressing this by implementing connection rate limiting at the WebSocket gateway layer and migrating legacy devices to more secure OCPP profiles (Security Profile 2 or 3).
Affected products
- EVoke Systems EVoke CSMS (Charging Station Management System) All versions
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory: CISA ICSA-26-176-02 published