top of page
perceptive_background_267k.jpg

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 08:03:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Mobile & IoT, Network Infrastructure

CVE-2026-44100 affects the CHARX JupiCore service, a component used in EV charging point management infrastructure. An unauthenticated remote attacker can exploit this vulnerability to reconfigure charging points without any credentials. The impact includes disclosure of charging point UIDs, Denial-of-Service conditions, and file tampering. The vulnerability is particularly concerning as it requires no authentication, lowering the barrier for exploitation. It affects critical EV charging infrastructure, which is increasingly widespread. The advisory was published by CERT VDE under VDE-2026-008. No user interaction or privileges are required to exploit this flaw, making it a high-severity issue.

Technical details

Mitigation steps:

Affected products:

CHARX JupiCore

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page