Ev.Energy provides electric vehicle charging management and energy optimization software, where its disclosures concentrate on authentication and session-management weaknesses such as improper restriction of excessive authentication attempts, insufficient session expiration, insufficiently protected credentials, and missing authentication for critical functions. These patterns reflect the authentication-sensitive boundary between user-facing applications and grid-connected charging infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ev.Energy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27772CRITICAL WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sent to the backend. An unauthenti | Feb 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-24445CRITICAL The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allow an attacker to conduct denial | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-26290CRITICAL The WebSocket backend uses charging station identifiers to uniquely
associate sessions but allows multiple endpoints to connect using the
same session identifier. This implementa | Feb 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-25774MEDIUM Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | Feb 27, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ev.Energy.
Media articles that mention a CVE ID that affects a product developed by Ev.Energy — matched by CVE ID, not by vendor name.