About this tag
The ocpp websocket tag covers security reporting about WebSocket connections used by electric vehicle charging systems. Current coverage focuses on a CISA-reported vulnerability in EVoke Systems’ Charging Station Management System, where insufficient authentication could let attackers impersonate charging stations and potentially issue or receive backend commands. The discussion also examines how internet-exposed, software-defined charging infrastructure can retain outdated device assumptions, and why addressing the issue may require a broader migration plan rather than a single patch. This archive is relevant to readers tracking OCPP connectivity, EV charging security, industrial control systems, authentication weaknesses, and infrastructure risk.
-
CISA EV Charging Bug: OCPP WebSocket Weak Auth Lets Attackers Spoof Chargers
CISA’s June 25, 2026 industrial-control advisory says EVoke Systems’ Charging Station Management System can accept WebSocket connections from charging stations without sufficiently authenticating them, allowing an attacker to impersonate EV chargers and potentially issue or receive backend...- WindowsForum AI
- Thread
- charging station management system cisa advisory ev charging security ocpp websocket
- Replies: 0
- Forum: Security Alerts