[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-four-flaws-in-montas-ev-charger-platform-risk-takeover":10,"sections":46},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":35,"tags":36,"sources":41,"feedback":45,"feedback_at":22,"cost_usd":45,"total_tokens":45},9389,"four-flaws-in-montas-ev-charger-platform-risk-takeover","Four Flaws in Monta's EV Charger Platform Risk Takeover","CISA flagged four bugs, including a 9.4-severity missing-authentication flaw, letting attackers impersonate or hijack Monta charging stations.","Four newly disclosed vulnerabilities in Monta's EV charging platform could let attackers impersonate charging stations, brute-force their way into sessions, or seize administrative control of the network.\n\nCISA published an advisory on October 1 detailing four flaws in monta.app, the backend software Dutch company Monta uses to run its charging stations. The worst, rated 9.4 out of 10 on the CVSS scale, stems from WebSocket endpoints that skip authentication entirely, letting an attacker pose as a legitimate charger. Three more bugs compound the problem: no limit on failed login attempts, session identifiers that don't expire properly, and charging-station credentials that are findable through public mapping tools. All four affect every version of the platform, deployed worldwide. Monta says it has added rate limiting to block abusive connections and is working to expand authenticated access across its network, but for now the stronger protections remain opt-in.\n\nThat matters because EV chargers sit on the same critical-infrastructure list as power grids and transit systems, and this platform runs stations across multiple countries. An attacker who can impersonate a charger doesn't just inconvenience one driver; they can manipulate sessions, disrupt charging availability at scale, or use the foothold to probe further into connected energy systems. It is the same authentication-as-afterthought pattern that has dogged industrial and IoT gear for a decade, from default router passwords to unauthenticated SCADA links.\n\nOpt-in security is one of the oldest moves in connected-hardware history. Ship the fix, then let adoption lag for as long as customers allow it.","[\"ev-charging\",\"cybersecurity\",\"iot-security\",\"cisa\"]","2026-10-01T12:00:00.000Z","2026-10-02T15:24:59.343Z","2026-10-02T15:25:04.060Z","published",null,[24,30],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The piece claims every deployment stays exposed until operators manually enable Security Profile 2, but the source shows Monta already deployed automated mitigations (WebSocket rate limiting\u002Fthrottling for the brute-force flaw, and duplicate-connection handling for the session-collision flaw) — rewrite to note these existing mitigations so only the unauthenticated-WebSocket (9.4) issue is left wholly dependent on operator action.","resolved",{"id":31,"reviewer":32,"round":33,"reason":34,"status":29},"publisher-r2","publisher",2,"The closing sentence is a grammatically broken run-on\u002Fcomma-splice fragment ('opt-in security is one of the oldest moves in connected-hardware history, ship the fix, then let adoption lag for as long as customers allow it') that reads as unfinished rather than a polished closing line.","security",[37,38,39,40],"ev-charging","cybersecurity","iot-security","cisa",[42],{"name":43,"url":44},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-274-02",0,{"sections":47},[48,53,57,62,67,72,77,82,87,92,97,102,107,112],{"name":49,"slug":50,"count":51,"latest_published_at":52},"AI","ai",5722,"2026-10-02T04:00:00.000Z",{"name":54,"slug":35,"count":55,"latest_published_at":56},"Security",829,"2026-10-01T17:31:56.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Policy","policy",437,"2026-10-01T18:10:00.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Deals","deals",317,"2026-10-01T22:00:00.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Hardware","hardware",198,"2026-10-01T17:38:48.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Science","science",168,"2026-10-01T18:35:55.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Consumer Tech","consumer-tech",155,"2026-10-01T19:54:10.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Dev Tools","dev-tools",96,"2026-10-01T16:57:03.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Software","software",93,"2026-09-30T21:41:11.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Startups","startups",90,"2026-10-01T21:55:22.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"General","general",50,"2026-09-30T21:37:54.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":113,"slug":114,"count":115,"latest_published_at":116},"How-To","how-to",7,"2026-10-01T09:00:00.000Z"]