AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-25T05:00:00.000Z and has not been modified since then. The vulnerability affects EVoke Systems Charging Station Management System, specifically its WebSocket backend which uses charging station identifiers to associate sessions but allows multiple endpoints to connect using the same session identifi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-25T05:00:00.000Z and has not been modified since then. The WebSocket Application Programming Interface in EVoke Systems Charging Station Management System lacks restrictions on the number of authentication requests, potentially allowing denial-of-service and brute-force attacks. Organizations should [truncated]
The EVoke Systems Charging Station Management System is vulnerable due to publicly accessible charging station authentication identifiers via web-based mapping platforms. Organizations using EVoke Systems Charging Station Management System should prioritize inventory checks for affected chargers, assess their current security profiles, and engage with EVoke for remediation and mitigation strategies. The a [truncated]
The EVoke Systems Charging Station Management System has a critical vulnerability (CVE-2026-40702) due to WebSocket endpoints lacking proper authentication mechanisms. This allows attackers to impersonate charging stations, potentially leading to unauthorized access to sensitive data and privilege escalation. Organizations should be aware of the vulnerability's impact on their systems and take immediate a [truncated]