CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Hydro-Québec Le Circuit Electrique charging station backend

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 546

As cited

Copy frozen at (site build).

vulnerabilities

Hydro-Québec Le Circuit Electrique charging station backend

Hydro-Québec's Le Circuit Electrique charging station backend contains three critical vulnerabilities affecting versions prior to June 2026, including improper authentication on websocket endpoints, lack of throttling on authentication attempts, and insufficient session management. These flaws could enable privilege escalation, denial-of-service attacks, and backend overwhelm via malicious OCPP (Open Charge Point Protocol) clients. Hydro-Québec has mitigated the risks by disabling OCPP on most stations and implementing authentication systems on remaining affected infrastructure.

Why it matters: Electric vehicle charging infrastructure operators in Canada and those managing OCPP-dependent systems should verify their station versions and confirm remediation status with Hydro-Québec, as unauthenticated network access to charging backends creates both operational availability and potential supply chain risks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hydro-Québec Le Circuit Electrique charging station backend

Hydro-Québec's Le Circuit Electrique charging station backend contains three critical vulnerabilities affecting versions prior to June 2026, including improper authentication on websocket endpoints, lack of throttling on authentication attempts, and insufficient session management. These flaws could enable privilege escalation, denial-of-service attacks, and backend overwhelm via malicious OCPP (Open Charge Point Protocol) clients. Hydro-Québec has mitigated the risks by disabling OCPP on most stations and implementing authentication systems on remaining affected infrastructure.

Why it matters: Electric vehicle charging infrastructure operators in Canada and those managing OCPP-dependent systems should verify their station versions and confirm remediation status with Hydro-Québec, as unauthenticated network access to charging backends creates both operational availability and potential supply chain risks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary