CVE-2026-44622 Details
Description
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
A vulnerability exists in EVoke Systems Charging Station Management System (CSMS) that allows charging station authentication identifiers to be publicly accessed via web-based mapping platforms. This issue affects all versions of the EVoke CSMS.
EVoke is working with charger Original Equipment Manufacturers (OEMs) to upgrade devices to support stronger security profiles. For legacy chargers that cannot be updated, EVoke is implementing server-side protections to mitigate spoofing risks by only accepting identifiers from chargers registered in their inventory database. Additionally, the platform will monitor for session anomalies and connection rate limit at the WebSocket gateway to prevent denial-of-service attacks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
| CWE-522 | Insufficiently Protected Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| EVoke Systems Charging Station Management System | <= 0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion