Automated Logic WebCTRL Premium Server WebSocket Authentication Request Rate Limiting Vulnerability Allowing Denial-of-Service and Brute-Force Attacks

Vulnerability

A vulnerability exists in the WebSocket API of Automated Logic WebCTRL Premium Server, specifically in versions prior to 8.5 cumulative releases. The issue arises from a lack of rate limiting on authentication requests, which could enable an attacker to perform denial-of-service attacks by disrupting legitimate charger telemetry or to conduct brute-force attacks to gain unauthorized access.

Impact

Exploitation of this vulnerability could lead to denial-of-service conditions by misrouting or suppressing legitimate charger telemetry, or allow unauthorized access through successful brute-force attempts.

Remediation

For customers using supported versions of WebCTRL (WebCTRL 8.5 cumulative releases and later), Automated Logic provides secure configuration guidance for hardware and software deployments, BACnet Secure Connect support, and published best practices for network segmentation, access control, and secure protocol implementation. Additional information is available on the Automated Logic website.

Added: Mar 20, 2026, 11:34 PM
Updated: Mar 20, 2026, 11:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.6
exploitability
7.4
remediation
7.9
relevance
4.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.