SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-22099

HIGH · CVSS 8.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability exists in a charging station that lacks authentication for Bluetooth commands, allowing unauthorized users to access sensitive information, trigger device reboots, or initiate firmware updates. Organizations utilizing these charging stations should prioritize addressing this issue to mitigate the risks of unauthorized access and potential exploitation. Immediate action is recommended for manufacturers and users of affected products to secure their devices against potential attacks.

CVE
CVE-2026-22099
Severity
HIGH
CVSS
8.7
EPSS
0.19%

Original NVD Description

The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.