SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-44104

CRITICAL · CVSS 9.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The firmware update process for the charging controller's basemodule is vulnerable due to inadequate validation, relying solely on CRC32 checksum verification without cryptographic signature checks. This flaw enables unauthenticated remote attackers to install malicious firmware, potentially leading to complete system compromise. Organizations utilizing affected charging controllers should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-44104
Severity
CRITICAL
CVSS
9.8
EPSS
0.27%

Original NVD Description

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.