PatchSiren cyber security CVE debrief
CVE-2026-25113 SWITCH EV CVE debrief
CVE-2026-25113 is a network-reachable weakness in the SWTCH EV / swtchenergy.com WebSocket application interface where authentication requests are not rate-limited. According to CISA’s advisory, that gap may let an attacker suppress or mis-route legitimate charger telemetry, trigger denial-of-service conditions, or brute-force authentication to gain unauthorized access. The advisory was first published on 2026-02-26 and updated on 2026-05-14 (Update A) to correct vendor spelling and add SWTCH-provided mitigations.
- Vendor
- SWITCH EV
- Product
- SWTCH EV swtchenergy.com vers:all/*
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-05-14
Who should care
Operators of SWTCH EV charging deployments, EV charging fleet administrators, OT/ICS security teams, network defenders responsible for charger connectivity, and incident response teams should prioritize this issue—especially where the WebSocket API is exposed to untrusted devices or networks.
Technical summary
The advisory describes a lack of restrictions on the number of authentication requests against the WebSocket Application Programming Interface. CISA maps the issue to CWE-307 (Improper Restriction of Excessive Authentication Attempts) and rates it CVSS 3.1 7.5 HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The stated impacts are denial of service through telemetry suppression or mis-routing, and brute-force attempts that may lead to unauthorized access. The source revision history notes that Update A added mitigations from SWTCH, including added security checks for initial connections from untrusted chargers, broader connection-control and ingress-protection scrutiny, compensating controls such as monitoring and IP-based access controls, and device-specific upgrade paths where firmware and TLS compatibility allow.
Defensive priority
High. This is a remotely reachable authentication abuse issue with no privileges required and high availability impact. The advisory also indicates that some existing chargers may need compensating controls or upgrades due to legacy firmware and SSL/TLS compatibility constraints, so defenders should verify exposure and apply vendor guidance promptly.
Recommended defensive actions
- Confirm whether any SWTCH EV WebSocket endpoints are reachable from untrusted networks or devices.
- Apply SWTCH’s updated security policy and configuration changes for initial connections where supported.
- Use monitoring and targeted network-level restrictions, including IP-based access controls, to reduce exposure.
- Identify chargers with legacy firmware or SSL/TLS compatibility limitations and plan upgrades or retirement where full enforcement is not possible.
- Review telemetry integrity and authentication logs for signs of repeated authentication attempts, suppression, or mis-routing.
- Follow the SWTCH Security portal and contact SWTCH support for product-specific remediation guidance.
Evidence notes
All substantive findings come from the supplied CISA CSAF advisory (ICSA-26-057-06) and its revision history. The advisory states that the WebSocket API lacks restrictions on authentication requests and that this may enable denial-of-service or brute-force attacks. It also supplies the remediation notes added in Update A on 2026-05-14, including additional connection scrutiny, compensating controls, and upgrade guidance. The provided reference list includes CWE-307 and the official CVE record; no KEV entry was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25113 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25113
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25113 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25113
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.