Back

CRITICAL

EVMAPA Insufficient Session Expiration

Published Jan 22, 2026

Description

This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging sessions. The lack of proper session management and expiration control allows attackers to exploit this weakness by reusing valid charging station IDs to establish multiple sessions concurrently.

Affected products

Remediation

Vendor solution

EVMAPA informed CISA they have resolved this issue and do not allow simultaneous connection of charging stations with the same CBID.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Jan 22, 2026
Updated Jan 23, 2026
Reserved Aug 20, 2025

CISA Vulnrichment

Updated Jan 23, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Jan 22, 2026
Updated Jan 23, 2026

GitHub

No data