PatchSiren cyber security CVE debrief
CVE-2026-28204 CTEK CVE debrief
CISA's ICSA-26-078-06 reports that authentication identifiers for CTEK Chargeportal charging stations are publicly accessible through web-based mapping platforms. The advisory rates the issue CVSS 6.5 (medium) and publishes it on 2026-03-19. CTEK's remediation note says the product will be sunset in April 2026, so operators should reduce exposure now and plan migration.
- Vendor
- CTEK
- Product
- Chargeportal
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-19
- Original CVE updated
- 2026-03-19
- Advisory published
- 2026-03-19
- Advisory updated
- 2026-03-19
Who should care
Operators and administrators of CTEK Chargeportal deployments, EV charging station owners, OT/ICS security teams, and SOC staff who manage externally reachable asset identifiers or mapping integrations.
Technical summary
The advisory states that charging station authentication identifiers are publicly accessible via web-based mapping platforms. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5). While the corpus does not describe active exploitation, public exposure of identifiers can aid asset discovery and increase the risk of follow-on unauthorized access attempts.
Defensive priority
Medium
Recommended defensive actions
- Inventory all Chargeportal deployments and confirm whether station identifiers are exposed through public mapping services.
- Restrict or remove public exposure of authentication identifiers and review any integrations with web-based mapping platforms.
- Apply CISA ICS recommended practices, including least privilege, segmentation, and defense in depth.
- Work with CTEK support on remediation and migration planning because the product is slated for sunset in April 2026.
- Monitor for unusual access to station-management systems and validate that only intended identifiers are published externally.
Evidence notes
Grounded in CISA's CSAF advisory ICSA-26-078-06 and its linked CVE record. The advisory names the issue, states that charging station authentication identifiers are publicly accessible via web-based mapping platforms, provides the CVSS 3.1 vector 6.5, and notes CTEK's April 2026 sunset plan. No KEV entry is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28204 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28204
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28204 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28204
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.