Hydro-Québec Le Circuit Electrique charging station backend
Multiple vulnerabilities exist in Hydro-Québec Le Circuit Electrique charging station backend (versions prior to June 2026) related to improper access control (CWE-284), weak authentication mechanisms (CWE-307), and insufficient transport layer security (CWE-613). The vulnerabilities allow privilege escalation or denial-of-service attacks through the OCPP (Open Charge Point Protocol) interface. Hydro-Québec has mitigated the risk by disabling OCPP on the majority of stations and implementing authentication systems for stations that require OCPP to remain active.
- Network access to the charging station backend or OCPP interface
- Ability to send protocol messages to the OCPP endpoint
Patching may require device reboot — plan for process interruption
/api/v1/advisories/0f531d3b-95c5-472a-b1f7-87e50d467dd1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.