CVE-2026-31904 identifies a rate limiting vulnerability within the WebSocket API of the CTEK Chargeportal. Rated High with a CVSS score of 7.5, this flaw allows unauthenticated attackers to conduct denial-of-service attacks by overwhelming authentication requests, potentially suppressing charger telemetry or facilitating brute-force access. There is currently no evidence of active exploitation, public exploit code, or significant community attention, with a very low EPSS score and no inclusion in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ctek:charge_portal:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.