news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-40702

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.4 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Risk score
75.2
Published
2026-06-25
Status
Published

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

Weaknesses

CWE-306

Coverage 1

Advisories and references