the number of authentication requests. This absence of rate limiting may
allow an attacker to conduct denial-of-service attacks by suppressing
or mis-routing legitimate charger telemetry, or conduct brute-force
attacks to gain unauthorized access.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
SWITCH EV did not respond to CISA's request for coordination. Contact SWITCH EV using their contact page here: https://swtchenergy.com/contact/ for more information.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 05 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Mon, 02 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Swtchenergy
Swtchenergy swtchenergy.com |
|
| CPEs | cpe:2.3:a:swtchenergy:swtchenergy.com:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Swtchenergy
Swtchenergy swtchenergy.com |
Fri, 27 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Switch Ev
Switch Ev swtchenergy.com |
|
| Vendors & Products |
Switch Ev
Switch Ev swtchenergy.com |
Fri, 27 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access. | |
| Title | SWITCH EV swtchenergy.com Improper Restriction of Excessive Authentication Attempts | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-03-10T19:20:52.878Z
Reserved: 2026-02-23T23:48:14.377Z
Link: CVE-2026-25113
Updated: 2026-03-02T20:27:55.540Z
Status : Modified
Published: 2026-02-27T00:16:56.853
Modified: 2026-03-05T21:16:15.610
Link: CVE-2026-25113
No data.
OpenCVE Enrichment
Updated: 2026-04-16T16:00:13Z