CVE-2026-44102

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 07:16

Updated : 2026-07-30 16:17


NVD link : CVE-2026-44102

Mitre link : CVE-2026-44102

CVE.ORG link : CVE-2026-44102


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')