Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support .
Fri, 20 Mar 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access. | |
| Title | CTEK Chargeportal Improper Restriction of Excessive Authentication Attempts | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-03-20T22:45:17.571Z
Reserved: 2026-03-12T16:52:46.513Z
Link: CVE-2026-31904
No data.
Status : Received
Published: 2026-03-20T23:16:44.060
Modified: 2026-03-20T23:16:44.060
Link: CVE-2026-31904
No data.
OpenCVE Enrichment
No data.