PatchSiren cyber security CVE debrief
CVE-2025-54816 EVMAPA CVE debrief
CVE-2025-54816 is a critical authentication weakness in EVMAPA’s WebSocket-based charging-station communications. The CISA advisory says a WebSocket endpoint can be reached without proper authentication, allowing unauthorized users to establish connections and potentially access sensitive data or perform unauthorized actions. In an ICS/OT context, that can translate into privilege escalation and broader system impact if the endpoint is exposed or insufficiently isolated.
- Vendor
- EVMAPA
- Product
- Unknown
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-22
- Original CVE updated
- 2026-01-22
- Advisory published
- 2026-01-22
- Advisory updated
- 2026-01-22
Who should care
EVMAPA operators, charging-station maintainers, OT/ICS security teams, network administrators managing WebSocket or OCPP connectivity, and incident responders responsible for externally reachable industrial endpoints.
Technical summary
The source advisory assigns CVSS 3.1 9.4 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). CISA’s remediation note says some charging stations do not allow changes to the authorization key using OCPP, that operators may connect stations using WebSocket Secure (WSS), and that EVMAPA connects stations it supplies via its own VPN. For OCPP 2.x and newer stations, EVMAPA plans to implement BASIC authorization control.
Defensive priority
Immediate. This is a network-reachable, no-auth issue with high confidentiality and integrity impact. Even though the supplied enrichment does not mark it as KEV, exposed systems should be validated and contained as a priority.
Recommended defensive actions
- Identify whether any EVMAPA charging stations expose the affected WebSocket or OCPP interface.
- Enforce authentication and authorization on all WebSocket endpoints; do not rely on network placement alone.
- Prefer WSS and restrict access with VPN, allowlists, and OT/ICS network segmentation.
- Apply vendor guidance and monitor for unauthorized connection attempts or unexpected control actions.
- Track EVMAPA updates for BASIC authorization control on OCPP 2.x and newer stations, then retest after upgrades.
Evidence notes
All substantive claims in this debrief come from the supplied CISA CSAF advisory (ICSA-26-022-08 / CVE-2025-54816) and its listed references. The advisory’s initial publication and modified dates are both 2026-01-22T07:00:00Z, matching the supplied CVE timeline. The source explicitly describes unauthenticated WebSocket access, includes a CVSS 3.1 vector of 9.4, and links CISA ICS defensive guidance plus CWE-306 and CVSS references. The supplied enrichment does not indicate KEV inclusion.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-54816 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-54816
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-54816 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-54816
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-022-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.