CVE-2026-54479 Details
Description
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
A vulnerability exists in the WebSocket backend of EVoke Systems Charging Station Management System (CSMS) that allows multiple endpoints to connect using the same session identifier. This flaw leads to predictable session identifiers, which could enable unauthorized users to authenticate as other users. Additionally, it could allow a malicious actor to create a denial-of-service condition by flooding the backend with valid session requests.
EVoke is implementing several measures to address this vulnerability. For chargers that can be updated, EVoke will prioritize upgrades to support stronger security profiles. For legacy chargers that cannot be upgraded, additional server-side protections are being introduced. Moreover, EVoke will limit connections to a single active session per charger ID, monitor for session anomalies, and apply connection rate limiting to mitigate denial-of-service risks. For more information, contact EVoke through their website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| EVoke Systems Charging Station Management System | <= 0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion