PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28204 CTEK CVE debrief

CISA's ICSA-26-078-06 reports that authentication identifiers for CTEK Chargeportal charging stations are publicly accessible through web-based mapping platforms. The advisory rates the issue CVSS 6.5 (medium) and publishes it on 2026-03-19. CTEK's remediation note says the product will be sunset in April 2026, so operators should reduce exposure now and plan migration.

Vendor
CTEK
Product
Chargeportal
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-19
Original CVE updated
2026-03-19
Advisory published
2026-03-19
Advisory updated
2026-03-19

Who should care

Operators and administrators of CTEK Chargeportal deployments, EV charging station owners, OT/ICS security teams, and SOC staff who manage externally reachable asset identifiers or mapping integrations.

Technical summary

The advisory states that charging station authentication identifiers are publicly accessible via web-based mapping platforms. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5). While the corpus does not describe active exploitation, public exposure of identifiers can aid asset discovery and increase the risk of follow-on unauthorized access attempts.

Defensive priority

Medium

Recommended defensive actions

  • Inventory all Chargeportal deployments and confirm whether station identifiers are exposed through public mapping services.
  • Restrict or remove public exposure of authentication identifiers and review any integrations with web-based mapping platforms.
  • Apply CISA ICS recommended practices, including least privilege, segmentation, and defense in depth.
  • Work with CTEK support on remediation and migration planning because the product is slated for sunset in April 2026.
  • Monitor for unusual access to station-management systems and validate that only intended identifiers are published externally.

Evidence notes

Grounded in CISA's CSAF advisory ICSA-26-078-06 and its linked CVE record. The advisory names the issue, states that charging station authentication identifiers are publicly accessible via web-based mapping platforms, provides the CVSS 3.1 vector 6.5, and notes CTEK's April 2026 sunset plan. No KEV entry is present in the supplied data.

Official resources

Publicly disclosed by CISA on 2026-03-19 as ICSA-26-078-06 / CVE-2026-28204. The supplied corpus does not list known exploitation, KEV inclusion, or ransomware use.