This vulnerability occurs when a WebSocket endpoint does not enforce
proper authentication mechanisms, allowing unauthorized users to
establish connections. As a result, attackers can exploit this weakness
to gain unauthorized access to sensitive data or perform unauthorized
actions. Given that no authentication is required, this can lead to
privilege escalation and potentially compromise the security of the
entire system.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

EVMAPA informed CISA some of their charging stations do not allow changes to the authorization key using the Open Charge Point Protocol (OCPP). Currently, charge point operators have the option to connect stations using WebSocket Secure (WSS), and EVMAPA connects stations they supply via their own VPN. For OCPP 2.x and newer stations, EVMAPA plans to implement BASIC authorization control.

History

Fri, 23 Jan 2026 08:00:00 +0900

Type Values Removed Values Added
Description This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Title EVMAPA Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-01-22T22:40:55.625Z

Reserved: 2025-08-20T20:20:15.065Z

Link: CVE-2025-54816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-22T23:15:49.953

Modified: 2026-01-22T23:15:49.953

Link: CVE-2025-54816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses