CVE-2026-40702 Details
Description
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
A vulnerability exists in the WebSocket endpoints of EVoke Systems Charging Station Management System (CSMS), all versions. The issue arises from a lack of proper authentication, allowing attackers to impersonate charging stations. This vulnerability could be exploited to gain unauthorized access to sensitive data or to perform unauthorized actions, potentially leading to privilege escalation and compromising the security of the entire system.
EVoke is working with charger Original Equipment Manufacturers (OEMs) to upgrade devices to support stronger security profiles. For legacy chargers that cannot be updated, EVoke is implementing additional server-side protections. More information can be obtained by contacting EVoke through their website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://evokesystems.com/contact-us/ | [email protected] | Vendor |
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-02.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| EVoke Systems Charging Station Management System | <= 0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion