CVE-2026-40702Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-25: 2Technical Details · 2026-06-25: 206-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40702 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to ga… https://www.cve.org/CVERecord?id=CVE-2026-40702 ----- Traducción: CVE-2026-40702 Los… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑40702, describing how unauthenticated WebSocket endpoints allow station impersonation, without addressing patches or exploitation evidence.

    0000033
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40702 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to ga… https://www.cve.org/CVERecord?id=CVE-2026-40702

    Post summary

    The snippet announces CVE-2026-40702, describing that WebSocket endpoints lack proper authentication, allowing attackers to impersonate charging stations.

    00000676
    57.7K followersView on X

Explore more