CISA has disclosed four vulnerabilities affecting Monta’s electric-vehicle charging platform. The agency says the issues could allow unauthorized administrative actions or denial-of-service activity, making identity controls and session handling a priority for charging operators.
Where the weaknesses appear
The advisory identifies missing authentication and rate-limiting controls, weaknesses involving sessions, and the use of publicly accessible identifiers. CISA assigns the group a maximum CVSS v3 base score of 9.4 and lists monta.app as affected across all versions at the time of publication.
The practical risk extends beyond a conventional web account. EV charging platforms coordinate users, chargers and operational services, so unauthorized administrative access can affect a distributed physical service. CISA says it is not aware of public exploitation targeting these vulnerabilities.
Mitigation and operational checks
Monta is working toward authenticated connections and says its platform supports OCPP 1.6 Security Profile 2. The company also applies throttling and rate limits. Operators should confirm which controls are active in their own tenant and charger estate instead of assuming that a supported feature is already enabled everywhere.
Security teams should review privileged accounts, revoke stale sessions, monitor failed authentication patterns and segment charger-management services from unrelated business systems. Any configuration change should be tested against charger availability and field-support procedures. Related developments in connected transport can be followed through SectechMedia’s vehicle and transportation security coverage.

Leave a Reply