Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.
Fri, 02 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests. | |
| Title | Monta monta.app Insufficient Session Expiration | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-02T21:30:37.104Z
Reserved: 2026-09-24T16:22:04.112Z
Link: CVE-2026-97212
No data.
Status : Received
Published: 2026-10-02T22:16:56.760
Modified: 2026-10-02T22:16:56.760
Link: CVE-2026-97212
No data.
OpenCVE Enrichment
No data.