


Perceptive Security
SOC/SIEM Consultancy

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 08:03:15
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Network Infrastructure
CVE-2026-44100 affects the CHARX JupiCore service, a component used in EV charging point management infrastructure. An unauthenticated remote attacker can exploit this vulnerability to reconfigure charging points without any credentials. The impact includes disclosure of charging point UIDs, Denial-of-Service conditions, and file tampering. The vulnerability is particularly concerning as it requires no authentication, lowering the barrier for exploitation. It affects critical EV charging infrastructure, which is increasingly widespread. The advisory was published by CERT VDE under VDE-2026-008. No user interaction or privileges are required to exploit this flaw, making it a high-severity issue.
Technical details
Mitigation steps:
Affected products:
CHARX JupiCore
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
