关键信息 ICS Advisory - Title: EV Energy ev.energy - Release Date: February 26, 2026 - Alert Code: ICSA-26-057-07 Summary - Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. Affected Versions - ev.energy vers:all/ (CVE-2026-27772, CVE-2026-24445, CVE-2026-26290, CVE-2026-25774) CVSS Score - Vendor: EV Energy - Equipment: EV Energy ev.energy - Score: v3 9.4 - Vulnerabilities: Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background - Critical Infrastructure Sectors: Energy, Transportation Systems - Countries/Areas Deployed: Worldwide - Company Headquarters Location: United Kingdom Vulnerabilities - CVE-2026-27772 - CVE-2026-24445 - CVE-2026-26290 - CVE-2026-25774 Acknowledgments - Khaled Sarieddine and Mohammad Ali Sayed reported these vulnerabilities to CISA Recommended Practices - Minimize network exposure for all control system devices and/or systems. - Locate control system networks and remote devices behind firewalls. - Use secure methods like Virtual Private Networks (VPNs) for remote access. - Perform proper impact analysis and risk assessment. - Implement recommended cybersecurity strategies. Revision History - Initial Release Date: 2026-02-26 Related Advisories - CloudCharge cloudcharge.se - Chargemap chargemap.com - Johnson Controls, Inc. Frick Controls Quantum HD - Pelco, Inc. Sarix Pro 3 Series IP Cameras Tags - Sector: Energy Sector, Transportation Systems Sector - Topics:** Industrial Control System Vulnerabilities, Industrial Control Systems