Automated Logic WebCTRL Premium Server Charging Station Authentication Identifier Exposure Vulnerability

Vulnerability

A vulnerability exists in Automated Logic WebCTRL Premium Server that allows charging station authentication identifiers to be accessed publicly through web-based mapping platforms. This issue arises from cleartext transmission of sensitive information, which can be intercepted and modified by an attacker. The vulnerability affects WebCTRL Premium Server versions 8.5 cumulative releases and later.

Impact

Exploitation of this vulnerability could enable an attacker to read, intercept, or modify communications related to charging station authentication.

Remediation

For customers using supported versions of WebCTRL (WebCTRL 8.5 cumulative releases and later), Automated Logic provides secure configuration guidance for hardware and software deployments, BACnet Secure Connect (BACnet/SC) support which introduces TLS encryption and mutual authentication, and published best practices for network segmentation, access control, and secure protocol implementation. Additional information is available on the Automated Logic website.

Added: Mar 20, 2026, 11:32 PM
Updated: Mar 20, 2026, 11:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
7.0
remediation
7.9
relevance
4.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.