Security Advisory

CVE-2026-44104

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 06:52:31
Last updated 2026-07-30 14:05:46
Assigner CERTVDE
CVSS score not scored
State PUBLISHED

Description

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.