CVE-2026-42952

Summary

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

Affected Software

VendorProductVersion RangeStatus
Hydro-QuébecLe Circuit Electrique charging station backend0 < June_2026affected

Weaknesses

  • CWE-307: CWE-307

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References