PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28204 CTEK CVE debrief

CISA's ICSA-26-078-06 reports that authentication identifiers for CTEK Chargeportal charging stations are publicly accessible through web-based mapping platforms. The advisory rates the issue CVSS 6.5 (medium) and publishes it on 2026-03-19. CTEK's remediation note says the product will be sunset in April 2026, so operators should reduce exposure now and plan migration.

Vendor
CTEK
Product
Chargeportal
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-19
Original CVE updated
2026-03-19
Advisory published
2026-03-19
Advisory updated
2026-03-19

Who should care

Operators and administrators of CTEK Chargeportal deployments, EV charging station owners, OT/ICS security teams, and SOC staff who manage externally reachable asset identifiers or mapping integrations.

Technical summary

The advisory states that charging station authentication identifiers are publicly accessible via web-based mapping platforms. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5). While the corpus does not describe active exploitation, public exposure of identifiers can aid asset discovery and increase the risk of follow-on unauthorized access attempts.

Defensive priority

Medium

Recommended defensive actions

  • Inventory all Chargeportal deployments and confirm whether station identifiers are exposed through public mapping services.
  • Restrict or remove public exposure of authentication identifiers and review any integrations with web-based mapping platforms.
  • Apply CISA ICS recommended practices, including least privilege, segmentation, and defense in depth.
  • Work with CTEK support on remediation and migration planning because the product is slated for sunset in April 2026.
  • Monitor for unusual access to station-management systems and validate that only intended identifiers are published externally.

Evidence notes

Grounded in CISA's CSAF advisory ICSA-26-078-06 and its linked CVE record. The advisory names the issue, states that charging station authentication identifiers are publicly accessible via web-based mapping platforms, provides the CVSS 3.1 vector 6.5, and notes CTEK's April 2026 sunset plan. No KEV entry is present in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28204 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28204

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28204 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28204

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.