EV Energy是英国EV Energy公司的一个电动汽车充电软件平台。 EV Energy存在代码问题漏洞,该漏洞源于WebSocket后端使用充电站标识符唯一关联会话但允许多个端点使用相同会话标识符连接,可能导致会话劫持或影子攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27772 | 9.4 CRITICAL | EV Energy ev.energy Missing Authentication for Critical Function |
| CVE-2026-24445 | 7.5 HIGH | EV Energy ev.energy Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-25774 | 6.5 MEDIUM | EV Energy ev.energy Insufficiently Protected Credentials |
No comments yet