An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
References
| Link | Resource |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-008/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 07:16
Updated : 2026-07-30 14:31
NVD link : CVE-2026-44103
Mitre link : CVE-2026-44103
CVE.ORG link : CVE-2026-44103
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
