A critical vulnerability in the SteVe (v3.7.1) Open Charge Point Central System allows unauthenticated remote attackers to establish a WebSocket connection and issue arbitrary OCPP (Open Charge Point Protocol) requests. This flaw permits attackers to execute commands without authentication, leading to unauthorized access and manipulation of EV charging operations.
- GitHub Issue #1546 ( steve-community/steve#1546 )