Monta monta.app
October 1, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL
This advisory from CISA details multiple vulnerabilities in Monta monta.app, a charging station management platform. Successful exploitation could enable attackers to gain unauthorized administrative control over charging stations or disrupt charging services through denial-of-service attacks. The vulnerabilities include missing authentication, improper restriction of authentication attempts, insufficient session expiration, and insufficiently pr ๐ **Analyst Note:** The high CVSS score and global deployment in energy and transportation sectors make these vulnerabilities particularly dangerous, as they could allow attackers to disrupt critical infrastructure. Organizations using Monta should prioritize enabling OCPP 1.6 Security Profile 2 a
Key Takeaways
- The Monta monta.app charging station management platform contains multiple critical vulnerabilities, including missing authentication for WebSocket endpoints, which could allow attackers to impersonate charging stations and gain unauthorized administrative control.
- These vulnerabilities affect all versions of monta.app and carry a CVSS score of 9.4, impacting critical infrastructure sectors such as Energy and Transportation Systems worldwide.
- Monta is actively working to deprecate unauthenticated access and has implemented rate limiting at the WebSocket layer, but operators are encouraged to enable OCPP 1.6 Security Profile 2 for immediate protection.