CVE-2026-7849
- EPSS 0.42%
- Veröffentlicht 30.07.2026 07:16:59
- Zuletzt bearbeitet 30.07.2026 15:16:37
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
CVE-2026-44108
- EPSS 0.46%
- Veröffentlicht 30.07.2026 07:16:59
- Zuletzt bearbeitet 30.07.2026 14:31:21
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unaut...
CVE-2026-44107
- EPSS 0.31%
- Veröffentlicht 30.07.2026 07:16:59
- Zuletzt bearbeitet 30.07.2026 16:17:12
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-...
CVE-2026-44106
- EPSS 0.23%
- Veröffentlicht 30.07.2026 07:16:59
- Zuletzt bearbeitet 31.07.2026 23:17:24
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
CVE-2026-44105
- EPSS 0.09%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 30.07.2026 14:31:21
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
CVE-2026-44104
- EPSS 0.24%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 30.07.2026 15:16:33
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full...
CVE-2026-44103
- EPSS 0.24%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 30.07.2026 14:31:21
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the ...
CVE-2026-44102
- EPSS 0.21%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 30.07.2026 16:17:11
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during...
CVE-2026-44101
- EPSS 0.4%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 31.07.2026 23:17:23
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
CVE-2026-44100
- EPSS 0.28%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 30.07.2026 14:31:21
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.