Critical Vulnerability in EVoke Systems' Charging Station Software Exposes Unauthorized Access Risks
EVoke Systems' Charging Station Management Software is critically vulnerable due to inadequate authentication mechanisms in its WebSocket endpoints. This flaw allows attackers to impersonate charging stations, potentially leading to unauthorized access and privilege escalation. Immediate patching is advised as no known public exploitation has been reported yet.
Summary
On June 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory regarding a critical vulnerability in EVoke Systems' Charging Station Management Software (CSMS). The flaw, identified as CVE-2026-40702 with a CVSS score of 9.4, stems from insufficient authentication mechanisms in WebSocket endpoints. This oversight enables attackers to impersonate charging stations, facilitating unauthorized access and potential privilege escalation. While no public exploitation has been reported, the severity of this vulnerability necessitates immediate attention from affected organizations.
What Happened
The vulnerability lies within EVoke's CSMS software, where WebSocket endpoints lack proper authentication mechanisms. Attackers can exploit this weakness to impersonate charging stations, gaining unauthorized access to sensitive data or performing unauthorized actions. This flaw could lead to privilege escalation and compromise the security of the entire system. The advisory highlights the critical nature of this vulnerability due to its potential impact on operational technology environments.
Technical Details
The technical root cause is the absence of authentication requirements for WebSocket endpoints within EVoke's CSMS software. Attackers can exploit this by sending malicious requests that mimic legitimate charging station communications. This impersonation allows them to execute unauthorized commands or access sensitive information, posing a significant risk to system integrity and data confidentiality.
Affected Products and Fixed Versions
The vulnerability affects the EVoke CSMS product. As of the advisory date, no specific fixed versions were mentioned, underscoring the urgency for users to apply patches as soon as they become available from EVoke Systems.
Exploitation Status
No known public exploitation has been reported at this time. However, given the critical nature of the vulnerability and its potential impact, organizations using EVoke CSMS should assume that attackers may exploit it until a patch is applied.
Indicators of Compromise
Currently, no specific indicators of compromise (IoCs) have been identified or published in relation to this vulnerability. Organizations are advised to monitor their systems for unusual activities related to charging station communications and access patterns.
Detection Opportunities
Organizations can enhance detection by monitoring WebSocket traffic for unauthorized requests that could indicate an attempt to exploit this vulnerability. Implementing network segmentation and strict access controls around charging station management interfaces may also help in early detection of potential exploitation attempts.
Why This Matters for Defenders
This vulnerability highlights the critical importance of robust authentication mechanisms, especially in operational technology environments where physical assets are controlled. The ability for attackers to impersonate charging stations not only poses a risk to data integrity and confidentiality but also to the physical safety of users relying on these services. Immediate patching and monitoring are essential steps for defenders to mitigate this threat.
What Remains Unclear
- Specific details about how EVoke plans to address and patch this vulnerability have not been disclosed.
- The exact scope of affected versions within the EVoke CSMS product remains unspecified, leaving organizations uncertain about their exposure until further notice from EVoke Systems.
Defender Guidance
Defenders are advised to:
- Immediately contact EVoke Systems for information on patches or workarounds for CVE-2026-40702.
- Review and monitor WebSocket traffic related to charging station communications for signs of unauthorized access attempts.
- Implement network segmentation and strict access controls around systems managing charging stations to limit potential exploitation paths.
- Stay informed about updates from CISA regarding this vulnerability and any emerging indicators of compromise.
This critical vulnerability underscores the ongoing challenges in securing operational technology environments against sophisticated cyber threats. Immediate action is required from all affected parties to mitigate risks associated with CVE-2026-40702.
