CRITICAL vuln in Monta monta.app (CVE-2026-95102, CVSS 9.4): missing WebSocket auth lets attackers impersonate charging stations. Restrict endpoint access & monitor activity. More: https://radar.offseq.com/threat/cve-2026-95102-cwe-306-in-monta-montaapp-d0effdc35e6b46a2 #OffSeq #CVE202695102 #AppSec
Explore
~Cisa~
Unauthenticated WebSockets could enable admin takeover or charging disruption.
-
IOCs: CVE-2026-95102, CVE-2026-97363, CVE-2026-97212
-
#CVE202695102 #ICS #ThreatIntel
