Multiple Authentication and Session Vulnerabilities in Monta monta.app
Multiple vulnerabilities in the Monta monta.app platform allow unauthenticated remote attackers to hijack sessions, impersonate charging stations, and disrupt services via insecure WebSocket communication.
The Monta monta.app platform is affected by a series of critical vulnerabilities (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) related to insecure WebSocket management. These flaws stem from missing authentication for critical functions, inadequate rate limiting, and predictable session identifiers. Attackers can leverage the public availability of station identifiers to target the WebSocket backend, allowing them to impersonate valid charging stations or perform brute-force attacks against the authentication API. Because the backend does not sufficiently validate session integrity, an attacker can hijack existing station connections or trigger denial-of-service (DoS) conditions. These vulnerabilities impact the reliability of charging infrastructure globally, posing risks to both service availability and the security of sensitive operational data.
Impact
Successful exploitation can lead to unauthorized administrative control over charging stations, enabling attackers to modify charging parameters, exfiltrate station data, or disable charging services entirely. These vulnerabilities impact the Energy and Transportation sectors worldwide. If successfully exploited, an attacker could disrupt critical charging networks, resulting in denial-of-service or physical asset manipulation by authorized command spoofing.
Recommendation
- Enable OCPP 1.6 Security Profile 2 (HTTP Basic Authentication with TLS) for all managed charging stations to remediate the lack of authentication mechanisms (CVE-2026-95102).
- Configure robust rate limiting and connection throttling at the network edge to mitigate brute-force and DoS attempts against the WebSocket API (CVE-2026-97363).
- Monitor for anomalous WebSocket traffic patterns, specifically rapid reconnection attempts or excessive command volume directed at the charging station backend, which may indicate exploitation of CVE-2026-97212.
- Review public-facing web platforms and registries to limit the exposure of charging station authentication identifiers that facilitate targeted exploitation (CVE-2026-93474).
Immediate actions
Enable OCPP 1.6 Security Profile 2 for all connected charging infrastructure
Mitigations
Implement rate limiting and connection throttling at the WebSocket gateway level
CVE-2026-97363