As reported by CISA in advisory ICSA-26-274-02, four vulnerabilities in Monta's monta.app platform — including a CVSS 3.1 base score of 9.4 — expose EV charging infrastructure to unauthenticated station impersonation, session hijacking, and denial-of-service disruption. The advisory is notable not for a single smoking-gun flaw, but for what it reveals about the systemic authentication gaps still pervasive across the EV charging ecosystem.

Security Impact: As reported by CISA in advisory ICSA-26-274-02, four vulnerabilities in Monta's monta.app platform — including a CVSS 3.1 base score of 9.4 — expose EV charging infrastructure to unauthenticated station impersonation, session hijacking, and denial-of-service disruption.

Why This Matters Beyond the CVEs

The affected product spans all versions of monta.app, deployed across the Energy and Transportation Systems critical infrastructure sectors — and Monta's footprint is global. The core vulnerability, CVE-2026-95102, stems from WebSocket endpoints lacking proper authentication, which means the attack surface isn't a misconfiguration buried in an obscure setting: it's the default protocol behavior. Attackers can impersonate charging stations over the network without credentials, gaining administrative control or disrupting services at scale.

This is the class of problem that keeps OT defenders awake. EV charging stations are increasingly treated as distributed energy resources — endpoints that participate in load management, demand response, and grid interaction. When the management plane accepts unauthenticated station enrollment, the blast radius extends beyond individual chargers to the orchestration layer that utilities and grid operators rely on.

CVECVSS v3.1SeverityIssue
CVE-2026-951029.4CriticalMissing Authentication for Critical Function (WebSocket)
CVE-2026-973639.4CriticalImproper Restriction of Excessive Authentication Attempts
CVE-2026-972129.4CriticalInsufficient Session Expiration
CVE-2026-934749.4CriticalInsufficiently Protected Credentials
All four CVEs carry the same 9.4 critical score, which tells you the advisory is describing a single architectural weakness viewed from multiple angles — not four independent bugs. Fix the authentication model and you address the root cause.

Who Is Most Exposed

  • Charge point operators (CPOs) running Monta-managed stations without OCPP Security Profile 2 enabled — this is the default state for many deployments.
  • Fleet electrification programs where charging availability directly impacts operational uptime and revenue.
  • Public charging networks with high station density and internet-exposed WebSocket endpoints.
  • Utility demand-response participants whose stations feed telemetry into grid management systems.

Shield53 Recommendations

Immediate Actions:

  • Enable OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) on all Monta-managed stations immediately — Monta confirms this is supported and is the primary mitigation path.
  • Inventory all charging stations and identify which are running unauthenticated WebSocket connections. Prioritize internet-facing and public-facing units.
  • Implement network-level controls: restrict WebSocket traffic to known station IPs, enforce TLS inspection where feasible, and block unexpected outbound connections from station subnets.
  • Monitor for station ID brute-forcing and rapid reconnection patterns — these are the abuse signatures Monta's rate limiting targets, but your SOC should have independent visibility.
  • Review session token lifecycles and rotate any credentials provisioned before the advisory date.

Strategic Actions:

  • Map your EV infrastructure against IEC 62351 and NIST SP 800-82 Rev 3 guidance for OT authentication. The OCPP authentication gap is an industry-wide pattern, not a Monta-specific defect.
  • Push vendors for Security Profile 3 (certificate-based mutual TLS) adoption — Basic Auth over TLS is a floor, not a ceiling.
  • Integrate charging station telemetry into your OT monitoring stack. If you can't detect a station impersonation event, you can't respond to one.

The broader signal here: EV charging is now firmly in the OT threat landscape, and the authentication models that were acceptable for early-stage deployments won't survive contact with motivated adversaries. Treat every charging endpoint as you would any other industrial controller — because from a grid perspective, that's exactly what it is.