CVE-2026-27649 describes a session hijacking and shadowing vulnerability in WebSocket backends that use charging station identifiers for session management, potentially impacting systems like the CTEK Chargeportal. Rated 7.3 HIGH on the CVSS scale, this flaw is easily exploitable over the network without authentication or user interaction due to predictable session identifiers. Exploitation could lead to unauthorized user authentication, displacement of legitimate charging stations, and denial-of-service, resulting in low impacts to confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ctek:charge_portal:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.