Unauthenticated Remote Attack on CHARX JupiCore Service Leading to Reconfiguration of Charging Points
CVE-2026-44100

8.8HIGH

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44100?

The CHARX JupiCore service harbors a vulnerability that enables unauthenticated remote attackers to reconfigure charging points. This exploitation can result in the disclosure of sensitive charging point UIDs, potential Denial-of-Service conditions, and unauthorized file manipulation. Organizations utilizing the CHARX JupiCore service should take precautions to mitigate these risks and ensure the integrity and availability of their charging infrastructure.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.