Skip to content
TECH CEO Daily

CISA advisories flag EV charger, door access and IoT cloud flaws rated up to 9.8

Four October 1 advisories show chargers, badge systems and building controllers carry the same risks as IT, and one vendor has no fix planned.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1CISA said a missing-authentication flaw in Monta's charging platform, rated 9.4, could let attackers gain admin control of chargers.
  • 2Armatura One access control embeds an ActiveMQ flaw rated 9.8 that CISA's exploited-vulnerabilities catalog lists for ransomware use.
  • 3Meari did not respond to CISA and has no fix planned for authorization flaws in its IoT cloud service.

The news

On October 1, the US Cybersecurity and Infrastructure Security Agency (CISA) published industrial control system advisories covering four products that run buildings and vehicles rather than offices: Monta's electric-vehicle charging platform, Armatura One physical access control, the Meari IoT Cloud Platform and Johnson Controls (JCI) EasyIO Neo building controllers. CISA said it had no reports of public exploitation targeting any of them.

The most severe Monta issue, CVE-2026-95102, is a missing-authentication flaw rated 9.4 out of 10 on the CVSS severity scale. Three more Monta flaws, rated 7.5, 7.3 and 6.5, involve no limit on login attempts, predictable session identifiers that let attackers pose as other users, and charger login identifiers that are publicly visible on web mapping platforms. CISA said exploitation could give attackers administrative control of vulnerable charging stations or let them disrupt charging. The advisory covers all versions, and mitigations include enabling an authenticated, encrypted security profile in OCPP, the protocol chargers use to talk to their back end.

Armatura One, from US-based Armatura LLC, is a system that controls physical doors and entry. CISA listed five flaws. The worst, CVE-2023-46604, rated 9.8, is a known deserialization bug in the Apache ActiveMQ message broker embedded in the product, which CISA said can allow remote code execution before any login check. CISA noted that this ActiveMQ flaw is in its Known Exploited Vulnerabilities catalog because of ransomware campaigns, though it said it was not aware of attacks targeting Armatura One specifically. Other issues include a hard-coded encryption key, a vendor-defined default database superuser password and credentials written in plain text to logs. CISA advised upgrading to version 4.7.2, or 4.6.1 for the US edition.

The Meari advisory covers the company's IoT Cloud Platform OpenAPI service, which connects consumer and commercial devices such as cameras to the cloud. Two missing-authorization flaws could let a signed-in user change settings on devices they do not own, or read device data that CISA said exposes credentials, owner details and network data. CISA said Meari, which is based in China, did not respond to its coordination attempts and that no fix is planned.

The Johnson Controls flaw is less serious. CVE-2026-64892, rated 3.5 under CVSS v3.1 and 4.8 under v4.0, could expose sensitive information useful for later attacks on certain EasyIO Neo EC and CW controllers. Johnson Controls has released firmware V3.3b64 and V3.3b26 to fix it.

The numbers

Highest score (Armatura One, ActiveMQ flaw)
9.8
Monta missing-authentication flaw
9.4
Vulnerabilities across the four advisories
12
Meari fix status
No fix planned

Why CEOs should care

For CISOs, these products often sit outside the security team's inventory. Charging stations are bought by fleet or real estate teams, door systems by facilities, cameras by whoever needed them. Ask for a list of every cloud-managed building device, who owns it, and whether it can reach the corporate network. Armatura customers should confirm they are on 4.7.2 or 4.6.1, because the embedded ActiveMQ flaw is one ransomware groups have already used elsewhere.

For procurement leaders, the Meari case is the warning. A vendor that does not answer a US government agency is unlikely to answer you during an incident. Add facilities and IoT suppliers to the same vendor-risk questionnaire used for software: a vulnerability disclosure policy, patch timelines, and whether credentials or encryption keys are hard-coded.

For boards and CFOs, these systems control physical outcomes: whether doors open, whether vehicles charge, how buildings run. Ask management who is accountable for operational technology risk and whether insurance and incident response plans cover it.

The bigger picture

CISA's own mitigations for all four advisories repeat the same basics: keep control systems off the open internet, put them behind firewalls separate from business networks and use VPNs for remote access. Those steps are harder to follow when the product is cloud-managed by design, as Monta's and Meari's platforms are, which is why vendor security practices matter as much as network design.

What’s next

Monta and Johnson Controls customers should apply the configuration changes and firmware updates CISA listed, and Armatura customers should upgrade. Meari device owners have no patch to wait for, so the decision is whether to isolate or replace those devices.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

CISAMontaArmaturaMeariJohnson Controls

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.