Executive brief
The EVoke Systems Charging Station Management System (CSMS) is used to manage electric vehicle charging infrastructure. A vulnerability in how the system handles connections allows multiple devices to use the same session identifier, which is based on predictable charging station IDs. This could allow an attacker to impersonate a charging station, gain unauthorized access to user sessions, or disrupt charging services by overwhelming the system with requests.
Technical details
The WebSocket backend in EVoke CSMS uses charging station identifiers to uniquely associate sessions but fails to enforce single-connection limits per identifier. Because these identifiers are predictable, the implementation results in predictable session identifiers (CWE-613). A remote, unauthenticated attacker can exploit this by connecting to the backend using a known or guessed charger ID. This allows the attacker to either authenticate as another user/station or perform a denial-of-service attack by flooding the backend with valid session requests. The vendor is addressing this by implementing server-side protections, including allow-listing registered IDs and enforcing a single active connection per charger ID.
Affected products
- EVoke Systems EVoke CSMS All versions
Timeline
- 2026-06-25: advisory: CISA and NVD published the advisory.