PatchSiren cyber security CVE debrief
CVE-2026-40702 EVoke Systems CVE debrief
The EVoke Systems Charging Station Management System has a critical vulnerability (CVE-2026-40702) due to WebSocket endpoints lacking proper authentication mechanisms. This allows attackers to impersonate charging stations, potentially leading to unauthorized access to sensitive data and privilege escalation. Organizations should be aware of the vulnerability's impact on their systems and take immediate action to mitigate the risks. The vulnerability's severity and potential for unauthorized access make it essential for organizations to prioritize patching and compensating controls.
- Vendor
- EVoke Systems
- Product
- EVoke CSMS
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-25
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-25
- Advisory updated
- 2026-06-25
Who should care
Organizations using EVoke Systems Charging Station Management System, particularly those in the industrial control systems (ICS) sector, should be aware of this critical vulnerability and take immediate action to mitigate the risks. The vulnerability's severity and potential for unauthorized access make it essential for organizations to prioritize patching and compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability's impact on their systems and take necessary actions to prevent exploitation. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and tracking exceptions and retesting remediated assets to ensure the vulnerability is properly addressed. Additionally, organizations should monitor session anomalies and log security events to detect potential security incidents related to this vulnerability. By taking proactive measures, organizations can minimize the risk of unauthorized access and protect their systems from potential attacks. EVoke Systems Charging Station Management System users should also consider implementing additional server-side protections to mitigate spoofing risks and permit only a single active connection per charger ID to prevent exploitation. Furthermore, developing a lifecycle policy for legacy chargers can help organizations manage and mitigate the risks associated with outdated systems. By prioritizing patching, compensating controls, and proactive measures, organizations can effectively manage the risks associated with this critical vulnerability and protect their systems from potential attacks. It is essential for organizations to assign an owner for follow-up and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. This will help ensure that the necessary actions are taken to prevent exploitation and minimize the risk of unauthorized access. Overall, a comprehensive approach that includes patching, compensating controls, and proactive measures is necessary to effectively manage the risks associated with this critical vulnerability and
Technical summary
The EVoke Systems Charging Station Management System has a critical vulnerability (CVE-2026-40702) due to WebSocket endpoints lacking proper authentication mechanisms. This allows attackers to impersonate charging stations, potentially leading to unauthorized access to sensitive data and privilege escalation. The vulnerability affects organizations using EVoke Systems Charging Station Management System, particularly those in the industrial control systems (ICS) sector. Organizations should prioritize patching and compensating controls due to the critical severity and potential for unauthorized access.
Defensive priority
Organizations using EVoke Systems Charging Station Management System should prioritize patching and compensating controls due to the critical severity and potential for unauthorized access.
Recommended defensive actions
- Implement additional server-side protections to mitigate spoofing risks
- Permit only a single active connection per charger ID
- Monitor session anomalies and log security events
- Implement connection rate limiting at the WebSocket gateway layer
- Develop a lifecycle policy for legacy chargers
Evidence notes
The source advisory from CISA provides details on the vulnerability in EVoke Systems Charging Station Management System. WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. EVoke is working on mitigations and fixes, including upgrading to Security Profiles 2 or 3 for supported devices.
Official resources
-
CVE-2026-40702 CVE record
CVE.org
-
CVE-2026-40702 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-25T05:00:00.000Z and has not been modified since then.