CVE-2026-44099
- EPSS 0.23%
- Veröffentlicht 30.07.2026 07:16:58
- Zuletzt bearbeitet 30.07.2026 15:16:33
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
CVE-2026-44094
- EPSS 0.26%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 30.07.2026 15:16:33
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-...
CVE-2026-44098
- EPSS 1.37%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 30.07.2026 14:31:21
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be ...
CVE-2026-44097
- EPSS 0.24%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 30.07.2026 16:17:11
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lea...
CVE-2026-44096
- EPSS 0.23%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 31.07.2026 23:17:23
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
CVE-2026-44095
- EPSS 0.23%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 30.07.2026 14:31:21
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
CVE-2026-44093
- EPSS 0.23%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 30.07.2026 14:31:21
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
CVE-2026-44092
- EPSS 0.38%
- Veröffentlicht 30.07.2026 07:16:57
- Zuletzt bearbeitet 30.07.2026 16:17:11
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
CVE-2026-44091
- EPSS 0.33%
- Veröffentlicht 30.07.2026 07:16:56
- Zuletzt bearbeitet 31.07.2026 23:17:23
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
CVE-2026-44090
- EPSS 0.4%
- Veröffentlicht 30.07.2026 07:16:56
- Zuletzt bearbeitet 30.07.2026 14:31:21
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.