OS Command Injection Vulnerability in OCPP Backend by OEM
CVE-2026-44098
8.8HIGH
What is CVE-2026-44098?
A vulnerability exists in the OCPP backend system that permits an unauthenticated remote attacker to exploit a firewall bypass. This risk leads to OS command injection, allowing the execution of arbitrary commands under the limited privileges of the 'charx-oa' user. As a consequence, this could potentially disrupt charging operations and compromise system integrity. Immediate action is urged for users to apply the necessary patches to secure their systems.
Affected Version(s)
CHARX SEC-3000 1.0.0 < 1.9.1
CHARX SEC-3050 1.0.0 < 1.9.1
CHARX SEC-3100 1.0.0 < 1.9.1
