← voltar
CVE-2026-27649

CTEK Chargeportal Insufficient Session Expiration

CVSS 6.9 MEDIUMEPSS 0.3%CWE-613
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
20 mar 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Produtos afetados
CTEK · Chargeportal

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →