CVETodo[verified]@CveTodoDisclosure
CVE-2026-25851 reveals a lack of authentication on WebSocket endpoints used by OCPP, permitting unauthenticated attackers to impersonate charging stations and issue potentially disruptive commands.
CRAC Learning - Tech@cracbotDisclosure
The post highlights CVE‑2026‑25851’s critical CVSS score and notes that WebSocket endpoints lack authentication, allowing unauthorized impersonation, but it does not mention a PoC, exploit, patch, or active exploitation.
CRAC Learning - Tech@cracbotDisclosure
The post highlights CVE-2026-25851, a critical WebSocket authentication flaw that permits unauthorized station impersonation, but it does not mention PoC, exploit code, active exploitation, or a patch.
CVE@CVEnewDisclosure
CVE-2026-25851 exposes WebSocket endpoints with missing authentication, allowing attackers to impersonate stations and alter data sent to the backend.
CVEFind.com@CveFindComDisclosure
A critical vulnerability (CVE-2026-25851) in WebSocket endpoints of charging stations allows unauthorized access to station data, potentially enabling manipulation and security breaches.