CISA

Monta monta.app

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.

The following versions of Monta monta.app are affected:

monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)

Vendor

Equipment

Monta

Monta monta.app

Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials

Critical Infrastructure Sectors: Energy, Transportation Systems

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Netherlands

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unau...