This vulnerability occurs when the system permits multiple simultaneous
connections to the backend using the same charging station ID. This can
result in unauthorized access, data inconsistency, or potential
manipulation of charging sessions. The lack of proper session management
and expiration control allows attackers to exploit this weakness by
reusing valid charging station IDs to establish multiple sessions
concurrently.
connections to the backend using the same charging station ID. This can
result in unauthorized access, data inconsistency, or potential
manipulation of charging sessions. The lack of proper session management
and expiration control allows attackers to exploit this weakness by
reusing valid charging station IDs to establish multiple sessions
concurrently.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
EVMAPA informed CISA they have resolved this issue and do not allow simultaneous connection of charging stations with the same CBID.
Workaround
No workaround given by the vendor.
References
History
Fri, 23 Jan 2026 08:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging sessions. The lack of proper session management and expiration control allows attackers to exploit this weakness by reusing valid charging station IDs to establish multiple sessions concurrently. | |
| Title | EVMAPA Insufficient Session Expiration | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-01-22T22:32:48.138Z
Reserved: 2025-08-20T20:20:15.075Z
Link: CVE-2025-55705
No data.
Status : Received
Published: 2026-01-22T23:15:50.137
Modified: 2026-01-22T23:15:50.137
Link: CVE-2025-55705
No data.
OpenCVE Enrichment
No data.
Weaknesses