What is CVE-2026-44094?
CVE-2026-44094 allows an unauthenticated remote attacker to force the system to fall back to a firmware partition with an insecure configuration, including default credentials. This could enable the attacker to gain SSH access as an unprivileged 'user-app' user. Charging operations may be interrupted as a result.
Azərbaycanca: CVE-2026-44094 autentifikasiya olunmamış uzaqdan hücumçuya sistemin təhlükəli konfiqurasiyalı (default credential-lar daxil) firmware bölməsinə keçməsinə imkan verir. Bu zəiflik vasitəsilə hücumçu SSH ilə 'user-app' adlı imtiyazsız istifadəçi kimi sistemə daxil ola bilər. Nəticədə şarj prosesi dayandırıla bilər.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
As which user can a remote attacker exploiting CVE-2026-44094 gain SSH access?
The attacker can gain SSH access as an unprivileged 'user-app' user.
What impact can CVE-2026-44094 have on charging operations?
Charging operations may be interrupted as a result.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.