« Back to list

Ctek

Ctek Charge Portal: vulnerabilities and CVEs

Ctek Charge Portal has 3 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-31904High (8.7)0.78%—Mar 20, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or…
CVE-2026-27649Medium (6.9)0.47%—Mar 20, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session…
CVE-2026-25192Critical (9.3)0.48%—Mar 20, 2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1078 Valid Accounts1
  3. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.