CVETodo[verified]@CveTodoDisclosure
CVE-2026-24731 reveals that OCPP WebSocket endpoints allow unauthenticated access, permitting attackers to impersonate charging stations and send malicious commands.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqDisclosure
The tweet announces CVE-2026-24731 as a critical vulnerability affecting all EV2GO versions, describing unauthenticated WebSocket access that lets attackers control charging stations and corrupt data, and urges monitoring of network activity.
CRAC Learning - Tech@cracbotDisclosure
The post reports CVE‑2026‑24731 as a critical WebSocket authentication flaw that permits attackers to impersonate stations, but it does not provide a PoC, exploit, or patch information.
CRAC Learning - Tech@cracbotDisclosure
The post highlights CVE-2026-24731 as a critical WebSocket authentication flaw that permits unauthorized station impersonation, but it does not provide a PoC, exploit, or patch information.
CVE@CVEnewDisclosure
The CVE outlines that WebSocket endpoints lack proper authentication, enabling attackers to impersonate stations and manipulate data sent to the backend.
CVEFind.com@CveFindComDisclosure
The post announces a critical CVE (CVE-2026-24731) that allows unauthenticated attackers to control charging stations via WebSocket endpoints in the OCPP protocol, potentially manipulating network data.