Firmware Injection Vulnerability in JupiCore Service by JupiTech
CVE-2026-44103

6.9MEDIUM

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44103?

The JupiCore service from JupiTech is vulnerable to a remote code injection, allowing unauthorized attackers to inject malicious firmware into the internal charging module. This occurs due to the lack of proper integrity and verification checks during firmware updates. Exploitation of this vulnerability can lead to severe compromises of device integrity, potentially enabling further attacks in concert with related vulnerabilities.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.