As cited
Copy frozen at (site build).
vulnerabilities
Hydro-Québec Le Circuit Electrique charging station backend
Hydro-Québec's Le Circuit Electrique charging station backend contains three critical vulnerabilities affecting versions prior to June 2026, including improper authentication on websocket endpoints, lack of throttling on authentication attempts, and insufficient session management. These flaws could enable privilege escalation, denial-of-service attacks, and backend overwhelm via malicious OCPP (Open Charge Point Protocol) clients. Hydro-Québec has mitigated the risks by disabling OCPP on most stations and implementing authentication systems on remaining affected infrastructure.
Why it matters: Electric vehicle charging infrastructure operators in Canada and those managing OCPP-dependent systems should verify their station versions and confirm remediation status with Hydro-Québec, as unauthenticated network access to charging backends creates both operational availability and potential supply chain risks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Hydro-Québec Le Circuit Electrique charging station backend
Hydro-Québec's Le Circuit Electrique charging station backend contains three critical vulnerabilities affecting versions prior to June 2026, including improper authentication on websocket endpoints, lack of throttling on authentication attempts, and insufficient session management. These flaws could enable privilege escalation, denial-of-service attacks, and backend overwhelm via malicious OCPP (Open Charge Point Protocol) clients. Hydro-Québec has mitigated the risks by disabling OCPP on most stations and implementing authentication systems on remaining affected infrastructure.
Why it matters: Electric vehicle charging infrastructure operators in Canada and those managing OCPP-dependent systems should verify their station versions and confirm remediation status with Hydro-Québec, as unauthenticated network access to charging backends creates both operational availability and potential supply chain risks.
- Source published
- First seen by Cybersecurity Tracker