Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass in CTEK Chargeportal (CVE‑2026‑25192) Threatens Global EV Charging Infrastructure

A CVSS 9.4 authentication bypass (CVE‑2026‑25192) in CTEK Chargeportal allows attackers to impersonate charging stations and issue privileged OCPP commands. The flaw affects all deployed versions worldwide, exposing energy and transportation supply chains to potential service disruption and data corruption.

LiveThreat™ Intelligence · 📅 March 19, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

Critical Authentication Bypass in CTEK Chargeportal (CVE‑2026‑25192) Threatens Global EV Charging Infrastructure

What It Is – A critical authentication‑bypass flaw (CVE‑2026‑25192) in the CTEK Chargeportal management platform allows an unauthenticated actor to connect to the OCPP WebSocket endpoint, impersonate any charging station, and issue privileged commands. The vulnerability scores 9.4 (CVSS v3), indicating a severe risk of remote code execution, data manipulation, and service disruption.

Exploitability – The flaw is publicly disclosed by CISA; proof‑of‑concept code exists and the vulnerability is exploitable over the internet without credentials. No public exploit kits have been observed yet, but the low barrier to abuse makes active exploitation plausible.

Affected Products – All versions of CTEK Chargeportal (the web‑based portal used to monitor and control EV charging stations).

TPRM Impact –

  • Compromise of a charging‑station provider can cascade to fleet operators, utilities, and municipalities that rely on the platform.
  • Unauthorized control may corrupt usage data, affect billing, and disrupt energy‑load balancing, creating downstream supply‑chain risk.
  • The vulnerability spans Energy and Transportation sectors worldwide, exposing any third‑party that integrates CTEK Chargeportal into its operations.

Recommended Actions –

  • Apply the vendor‑released patch or upgrade to the latest supported version immediately.
  • Enforce network segmentation: isolate charging‑station traffic from corporate and OT networks.
  • Deploy TLS‑encrypted OCPP connections and enforce mutual authentication for all WebSocket endpoints.
  • Monitor for anomalous OCPP commands and failed authentication attempts.
  • Conduct a rapid risk assessment of all third‑party contracts that depend on CTEK Chargeportal and update contractual security clauses.

Source: CISA Advisory – ICSA‑26‑078‑06

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-06 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →