top of page
perceptive_background_267k.jpg

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Den…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 08:03:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Mobile & IoT, Identity & Access

CVE-2026-44101 describes a missing authentication vulnerability in the CHARX OCPP Agent service. An unauthenticated remote attacker can exploit this flaw to reconfigure the backend connection of the service. The vulnerability can result in Denial-of-Service conditions, potentially disrupting EV charging infrastructure. Additionally, confidential data may be disclosed to the attacker through the misconfigured backend connection. The CHARX product is an EV charging controller that uses the OCPP (Open Charge Point Protocol) for backend communication. No authentication is required to trigger the vulnerability, making it easily exploitable remotely. The issue was reported via CERT@VDE advisory VDE-2026-008. This poses a significant risk to critical infrastructure, particularly EV charging networks.

Technical details

Mitigation steps:

Affected products:

CHARX OCPP Agent

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page