CVE-2026-20882 describes a critical vulnerability in the WebSocket API, where a lack of rate limiting on authentication requests could enable denial-of-service or brute-force attacks against charger telemetry. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on availability, though confidentiality and integrity are not directly affected. There are no specific affected products listed, and it is not currently known to be actively exploited, nor is there public exploit code available in Metasploit, Nuclei, or ExploitDB. Despite its high severity, the EPSS score is very low, and while there's some community discussion and media coverage, it does not appear on CISA's KEV or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:mvm:mobiliti_e-mobi.hu:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.