Security/ ev-charging · cybersecurity · iot-security · cisa

Four Flaws in Monta's EV Charger Platform Risk Takeover

CISA flagged four bugs, including a 9.4-severity missing-authentication flaw, letting attackers impersonate or hijack Monta charging stations.

Four newly disclosed vulnerabilities in Monta's EV charging platform could let attackers impersonate charging stations, brute-force their way into sessions, or seize administrative control of the network.

CISA published an advisory on October 1 detailing four flaws in monta.app, the backend software Dutch company Monta uses to run its charging stations. The worst, rated 9.4 out of 10 on the CVSS scale, stems from WebSocket endpoints that skip authentication entirely, letting an attacker pose as a legitimate charger. Three more bugs compound the problem: no limit on failed login attempts, session identifiers that don't expire properly, and charging-station credentials that are findable through public mapping tools. All four affect every version of the platform, deployed worldwide. Monta says it has added rate limiting to block abusive connections and is working to expand authenticated access across its network, but for now the stronger protections remain opt-in.

That matters because EV chargers sit on the same critical-infrastructure list as power grids and transit systems, and this platform runs stations across multiple countries. An attacker who can impersonate a charger doesn't just inconvenience one driver; they can manipulate sessions, disrupt charging availability at scale, or use the foothold to probe further into connected energy systems. It is the same authentication-as-afterthought pattern that has dogged industrial and IoT gear for a decade, from default router passwords to unauthenticated SCADA links.

Opt-in security is one of the oldest moves in connected-hardware history. Ship the fix, then let adoption lag for as long as customers allow it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →