PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-54816 EVMAPA CVE debrief

CVE-2025-54816 is a critical authentication weakness in EVMAPA’s WebSocket-based charging-station communications. The CISA advisory says a WebSocket endpoint can be reached without proper authentication, allowing unauthorized users to establish connections and potentially access sensitive data or perform unauthorized actions. In an ICS/OT context, that can translate into privilege escalation and broader system impact if the endpoint is exposed or insufficiently isolated.

Vendor
EVMAPA
Product
Unknown
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-22
Original CVE updated
2026-01-22
Advisory published
2026-01-22
Advisory updated
2026-01-22

Who should care

EVMAPA operators, charging-station maintainers, OT/ICS security teams, network administrators managing WebSocket or OCPP connectivity, and incident responders responsible for externally reachable industrial endpoints.

Technical summary

The source advisory assigns CVSS 3.1 9.4 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). CISA’s remediation note says some charging stations do not allow changes to the authorization key using OCPP, that operators may connect stations using WebSocket Secure (WSS), and that EVMAPA connects stations it supplies via its own VPN. For OCPP 2.x and newer stations, EVMAPA plans to implement BASIC authorization control.

Defensive priority

Immediate. This is a network-reachable, no-auth issue with high confidentiality and integrity impact. Even though the supplied enrichment does not mark it as KEV, exposed systems should be validated and contained as a priority.

Recommended defensive actions

  • Identify whether any EVMAPA charging stations expose the affected WebSocket or OCPP interface.
  • Enforce authentication and authorization on all WebSocket endpoints; do not rely on network placement alone.
  • Prefer WSS and restrict access with VPN, allowlists, and OT/ICS network segmentation.
  • Apply vendor guidance and monitor for unauthorized connection attempts or unexpected control actions.
  • Track EVMAPA updates for BASIC authorization control on OCPP 2.x and newer stations, then retest after upgrades.

Evidence notes

All substantive claims in this debrief come from the supplied CISA CSAF advisory (ICSA-26-022-08 / CVE-2025-54816) and its listed references. The advisory’s initial publication and modified dates are both 2026-01-22T07:00:00Z, matching the supplied CVE timeline. The source explicitly describes unauthenticated WebSocket access, includes a CVSS 3.1 vector of 9.4, and links CISA ICS defensive guidance plus CWE-306 and CVSS references. The supplied enrichment does not indicate KEV inclusion.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-54816 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-54816

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-54816 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-54816

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-022-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.