What is CVE-2026-44104?
CVE-2026-44104 is a vulnerability in the firmware update process of a charging controller's basemodule, where only a CRC32 checksum is validated without cryptographic signature verification. This allows an unauthenticated remote attacker to install modified firmware, leading to full system compromise. Affected users should apply updates from the vendor immediately.
Azərbaycanca: CVE-2026-44104, doldurma nəzarət cihazının baza modulunda proqram təminatı yeniləmə prosesinin yalnız CRC32 yoxlama cəmini təsdiqlədiyi, kriptoqrafik imza doğrulaması aparmadığı üçün autentifikasiya olunmamış uzaqdan təcavüzkarın dəyişdirilmiş proqram təminatı yerləşdirərək tam sistem komprometinə nail olmasına imkan verən boşluqdur. Təsirə məruz qalan sistemlərdə istehsalçıdan ən son yeniləmələrin tətbiqi tövsiyə olunur.
FAQ2
In which component was the CVE-2026-44104 vulnerability discovered?
The CVE-2026-44104 vulnerability was discovered in the basemodule of a charging controller.
What impact can an attacker have by exploiting the CVE-2026-44104 vulnerability?
An unauthenticated remote attacker can achieve full system compromise by installing modified firmware.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.