


Perceptive Security
SOC/SIEM Consultancy

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 15:06:27
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Network Infrastructure
CVE-2026-44100 affects the CHARX JupiCore service, a component used in electric vehicle charging infrastructure. An unauthenticated remote attacker can exploit this vulnerability to reconfigure charging points without any authentication. The exploitation can result in multiple impacts including disclosure of charging point UIDs, Denial-of-Service conditions, and tampering with files. The vulnerability is particularly concerning as it targets EV charging infrastructure, which is considered critical infrastructure. No authentication is required to exploit this flaw, making it accessible to a wide range of threat actors. The issue has been documented by CERT VDE under advisory VDE-2026-008.
Technical details
Mitigation steps:
Affected products:
CHARX JupiCore
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
