top of page
perceptive_background_267k.jpg

The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This a…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 15:06:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities

CVE-2026-44104 describes a critical vulnerability in the firmware update process of a charging controller's basemodule. The update mechanism only validates a CRC32 checksum and does not perform cryptographic signature verification. This flaw allows an unauthenticated remote attacker to install malicious or modified firmware onto the device. Successful exploitation results in a full system compromise of the charging controller. The vulnerability is classified as high severity and was disclosed via NVD and CERT VDE advisory VDE-2026-008. No authentication is required to exploit this weakness, making it particularly dangerous in network-accessible deployments. The lack of secure boot or signed firmware validation represents a fundamental security design gap. This type of vulnerability is especially concerning in critical infrastructure and EV charging environments.

Technical details

Mitigation steps:

Affected products:

Charging Controller Basemodule Firmware

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page