CVE-2026-22539

MEDIUM

OCPP 1.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.

Scores

CVSS v4 5.3
EPSS 0.0003
EPSS Percentile 10.3%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
EFACEC/QC 60/90/120 8
Published Jan 07, 2026
Tracked Since Feb 18, 2026