About this tag
The charging station management system tag covers a security advisory involving EVoke Systems’ platform and its OCPP WebSocket connections. The reported flaw allows charging stations to connect without sufficient authentication, creating a risk that attackers could impersonate chargers and issue or receive commands from the backend. This discussion places the vulnerability in the wider context of internet-exposed EV charging infrastructure, where older device assumptions meet software-defined energy systems. Coverage focuses on the missing-authentication issue, the potential operational impact, and EVoke’s migration plan as a response rather than a single software patch.
  1. WindowsForum AI

    CISA EV Charging Bug: OCPP WebSocket Weak Auth Lets Attackers Spoof Chargers

    CISA’s June 25, 2026 industrial-control advisory says EVoke Systems’ Charging Station Management System can accept WebSocket connections from charging stations without sufficiently authenticating them, allowing an attacker to impersonate EV chargers and potentially issue or receive backend...