WebSocket Authentication Flaw in Hydro-Québec Charging Station

⚠️ CVE-Referenzen: CVE-2026-20744
Hydro-québec - Le Circuit Electrique Charging Station Backend - CRITICAL - CVE-2026-20744. The Hydro-Québec charging station features a WebSocket endpoint that allows unauthenticated connections. This security oversight can lead to privilege escalation, enabling unauthorized users to access sensitive functionalities and potentially compromise the integrity of the system. Proper authentication mechanisms should be implemented to safeguard against unauthorized access and ensure the security of the infrastructure.
Quelle: securityvulnerability.io