


Perceptive Security
SOC/SIEM Consultancy

The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This a…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 15:06:27
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities
CVE-2026-44104 describes a critical vulnerability in the firmware update process of a charging controller's basemodule. The update mechanism only validates a CRC32 checksum and does not perform cryptographic signature verification. This flaw allows an unauthenticated remote attacker to install malicious or modified firmware onto the device. Successful exploitation results in a full system compromise of the charging controller. The vulnerability is classified as high severity and was disclosed via NVD and CERT VDE advisory VDE-2026-008. No authentication is required to exploit this weakness, making it particularly dangerous in network-accessible deployments. The lack of secure boot or signed firmware validation represents a fundamental security design gap. This type of vulnerability is especially concerning in critical infrastructure and EV charging environments.
Technical details
Mitigation steps:
Affected products:
Charging Controller Basemodule Firmware
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
