PatchSiren cyber security CVE debrief
CVE-2026-28204 CTEK CVE debrief
CISA's ICSA-26-078-06 reports that authentication identifiers for CTEK Chargeportal charging stations are publicly accessible through web-based mapping platforms. The advisory rates the issue CVSS 6.5 (medium) and publishes it on 2026-03-19. CTEK's remediation note says the product will be sunset in April 2026, so operators should reduce exposure now and plan migration.
- Vendor
- CTEK
- Product
- Chargeportal
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-19
- Original CVE updated
- 2026-03-19
- Advisory published
- 2026-03-19
- Advisory updated
- 2026-03-19
Who should care
Operators and administrators of CTEK Chargeportal deployments, EV charging station owners, OT/ICS security teams, and SOC staff who manage externally reachable asset identifiers or mapping integrations.
Technical summary
The advisory states that charging station authentication identifiers are publicly accessible via web-based mapping platforms. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5). While the corpus does not describe active exploitation, public exposure of identifiers can aid asset discovery and increase the risk of follow-on unauthorized access attempts.
Defensive priority
Medium
Recommended defensive actions
- Inventory all Chargeportal deployments and confirm whether station identifiers are exposed through public mapping services.
- Restrict or remove public exposure of authentication identifiers and review any integrations with web-based mapping platforms.
- Apply CISA ICS recommended practices, including least privilege, segmentation, and defense in depth.
- Work with CTEK support on remediation and migration planning because the product is slated for sunset in April 2026.
- Monitor for unusual access to station-management systems and validate that only intended identifiers are published externally.
Evidence notes
Grounded in CISA's CSAF advisory ICSA-26-078-06 and its linked CVE record. The advisory names the issue, states that charging station authentication identifiers are publicly accessible via web-based mapping platforms, provides the CVSS 3.1 vector 6.5, and notes CTEK's April 2026 sunset plan. No KEV entry is present in the supplied data.
Official resources
-
CVE-2026-28204 CVE record
CVE.org
-
CVE-2026-28204 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Publicly disclosed by CISA on 2026-03-19 as ICSA-26-078-06 / CVE-2026-28204. The supplied corpus does not list known exploitation, KEV inclusion, or ransomware use.