CVE-2026-22539

MEDIUM

EFACEC QC 60/90/120 - Unauthenticated Information Disclosure via OCPP v1.6

Title source: llm
STIX 2.1

Description

As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.

References (1)

Core 1
Core References

Scores

CVSS v4 5.3
EPSS 0.0019
EPSS Percentile 8.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
EFACEC/QC 60/90/120 8
Published Jan 07, 2026
Tracked Since Feb 18, 2026