Hydro-Québec Le Circuit Electrique charging station backend

Plan PatchCVSS 9.8ICS-CERT ICSA-26-188-01Jul 7, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities exist in Hydro-Québec Le Circuit Electrique charging station backend (versions prior to June 2026) related to improper access control (CWE-284), weak authentication mechanisms (CWE-307), and insufficient transport layer security (CWE-613). The vulnerabilities allow privilege escalation or denial-of-service attacks through the OCPP (Open Charge Point Protocol) interface. Hydro-Québec has mitigated the risk by disabling OCPP on the majority of stations and implementing authentication systems for stations that require OCPP to remain active.

What this means
What could happen
An attacker with network access to the charging station backend could gain elevated privileges or shut down the charging service, potentially disrupting electric vehicle charging operations across multiple stations.
Who's at risk
This vulnerability affects electric vehicle charging station operators, particularly those managing Hydro-Québec Le Circuit Electrique stations. Any municipality or utility running public EV charging infrastructure is at risk if stations use OCPP protocol without proper authentication.
How it could be exploited
An attacker on the network could exploit missing authentication controls in the OCPP (Open Charge Point Protocol) interface to send unauthenticated commands to the charging station backend, bypassing access controls and either escalating privileges to administrative level or triggering a denial-of-service condition.
Prerequisites
  • Network access to the charging station backend or OCPP interface
  • Ability to send protocol messages to the OCPP endpoint
remotely exploitableno authentication requiredlow complexityaffects critical infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (1)
ProductAffected VersionsFix Status
Le Circuit Electrique charging station backend<June 2026No fix yet
Remediation & Mitigation
0/3
Do now
0/2
HOTFIXContact Hydro-Québec to verify your charging stations have been updated to disable OCPP, or confirm authentication systems have been implemented if OCPP must remain enabled
HARDENINGRestrict network access to the charging station backend to authorized management networks only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGMonitor OCPP traffic for unauthorized access attempts and implement network segmentation to isolate charging station backends from public networks
API: /api/v1/advisories/0f531d3b-95c5-472a-b1f7-87e50d467dd1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Hydro-Québec Le Circuit Electrique charging station backend | CVSS 9.8 - OTPulse