EV2GO是俄罗斯EV2GO公司的一个电动汽车充电设施管理平台。 EV2GO存在访问控制错误漏洞,该漏洞源于WebSocket端点缺乏适当的身份验证机制,可能导致未经身份验证的攻击者执行未经授权的站点模拟、权限提升以及对充电基础设施的未授权控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-25945 | 7.5 HIGH | EV2GO ev2go.io Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-20895 | 7.3 HIGH | EV2GO ev2go.io Insufficient Session Expiration |
| CVE-2026-22890 | 6.5 MEDIUM | EV2GO ev2go.io Insufficiently Protected Credentials |
No comments yet