Enable OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) as recommended by vendor Monta. Apply rate limiting and automated connection throttling at the WebSocket layer to block abusive patterns such as rapid reconnection, ID brute-forcing, and excessive command volume. Monitor for unauthorized administrative access or service disruptions at charging stations.
Quick answers
What is CVE-2026-97212?
Enable OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) as recommended by vendor Monta. Apply rate limiting and automated connection throttling at the WebSocket layer to block abusive patterns such as rapid reconnection, ID brute-forcing, and excessive command volume. Monitor for unauthorized administrative access or service disruptions at charging stations.
How severe is CVE-2026-97212?
critical, CVSS 9.4
Is CVE-2026-97212 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-97212 be mitigated?
Enable OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) as recommended by vendor Monta. Apply rate limiting and automated connection throttling at the WebSocket layer to block abusive patterns such as rapid reconnection, ID brute-forcing, and excessive command volume. Monitor for unauthorized administrative access or service disruptions at charging stations.
CVSS
9.4
Vendor
Monta
Published
Oct 4, 2026 · 04:43
Patch
Unknown / not confirmed
Affected products
Monta monta.app
Mitigation
Enable OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) as recommended by vendor Monta. Apply rate limiting and automated connection throttling at the WebSocket layer to block abusive patterns such as rapid reconnection, ID brute-forcing, and excessive command volume. Monitor for unauthorized administrative access or service disruptions at charging stations.
The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-274-02 disclosing four vulnerabilities in Monta monta.app, a widely used electric vehicle charging station management platform. The flaws span missing authentication, lack of rate limiting on WebSocket endpoints, predictable session identifiers, and insufficiently protected credentials. All versions of the software are affected. While no active exploitation has been confirmed, the CVSS scores range from 7.5 to 9.4, classifying three as Critical and one as High severity. The advisory urges operators to enable OCPP 1.6 Security Profile 2 and apply interim mitigations such as rate limiting.