Firmware Update Vulnerability in OCPP Backend by Affected Vendor
CVE-2026-44102

6.9MEDIUM

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44102?

The vulnerability allows an unauthenticated remote attacker to initiate a firmware update download through the OCPP backend by providing an invalid firmware file. This action leads to the firmware file being temporarily accessible due to inadequate locking mechanisms during the cleanup process, posing a security risk to the affected systems.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.