What is CVE-2026-44102?
CVE-2026-44102 is a vulnerability where an unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. Due to improper locking during the cleanup process, the file remains temporarily accessible, potentially exposing the system. It is recommended to enforce strict validation of OCPP requests to protect firmware integrity.
Azərbaycanca: CVE-2026-44102, autentifikasiya olunmamış uzaqdan hücumçunun OCPP backend vasitəsilə yanlış firmware faylı təqdim edərək firmware yeniləməsi yükləməsinə səbəb ola biləcəyi bir zəiflikdir. Bu zəiflik, təmizləmə prosesi zamanı düzgün locking mexanizmi olmaması səbəbindən faylın qısa müddət ərzində əlçatan qalmasına yol açır. Təsirə məruz qalan sistemlərdə firmware bütövlüyünü qorumaq üçün OCPP protokolu üzərindən gələn tələblərin ciddi yoxlanılması tövsiyə olunur.
FAQ2
Through which protocol can an attacker exploit the CVE-2026-44102 vulnerability?
CVE-2026-44102 is a vulnerability where an unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file.
What is the root cause of CVE-2026-44102?
The vulnerability is due to improper locking during the cleanup process, which leaves the file temporarily accessible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.