8.7

CVSS4.0

CVE-2026-3273 - Tenda F453 httpd AdvSetWrlsafeset formWrlsafeset buffer overflow

A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of the argument mit_ssid_index leads to buffer overflow. The attack can be executed remotely. The exploi…

πŸ“… Published: Feb. 27, 2026, 12:32 a.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-22878 - Mobility46 mobility46.se Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

πŸ“… Published: Feb. 27, 2026, 12:25 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

6.9

CVSS4.0

CVE-2026-27647 - Mobility46 mobility46.se Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent con…

πŸ“… Published: Feb. 27, 2026, 12:23 a.m. πŸ”„ Last Modified: April 16, 2026, midnight

8.7

CVSS4.0

CVE-2026-26305 - Mobility46 mobility46.se Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gai…

πŸ“… Published: Feb. 27, 2026, 12:22 a.m. πŸ”„ Last Modified: April 16, 2026, 6 a.m.

9.3

CVSS4.0

CVE-2026-27028 - Mobility46 mobility46.se Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, th…

πŸ“… Published: Feb. 27, 2026, 12:20 a.m. πŸ”„ Last Modified: April 16, 2026, midnight

6.5

CVSS3.1

CVE-2021-4456 - Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may hav…

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker…

πŸ“… Published: Feb. 27, 2026, 12:16 a.m. πŸ”„ Last Modified: March 3, 2026, 8:25 p.m.

6.9

CVSS4.0

CVE-2026-25774 - EV Energy ev.energy Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

πŸ“… Published: Feb. 27, 2026, 12:15 a.m. πŸ”„ Last Modified: April 15, 2026, 8:15 p.m.

6.9

CVSS4.0

CVE-2026-26290 - EV Energy ev.energy Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent con…

πŸ“… Published: Feb. 27, 2026, 12:13 a.m. πŸ”„ Last Modified: April 16, 2026, 6 a.m.

8.7

CVSS4.0

CVE-2026-24445 - EV Energy ev.energy Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gai…

πŸ“… Published: Feb. 27, 2026, 12:11 a.m. πŸ”„ Last Modified: April 16, 2026, 6 a.m.

9.3

CVSS4.0

CVE-2026-27772 - EV Energy ev.energy Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, th…

πŸ“… Published: Feb. 27, 2026, 12:09 a.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.
Total resulsts: 349182
Page 1413 of 34,919
Β« previous page Β» next page
Filters