


Perceptive Security
SOC/SIEM Consultancy

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Den…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 15:06:28
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Identity & Access, Network Infrastructure
CVE-2026-44101 is a critical vulnerability in the CHARX OCPP Agent service caused by missing authentication. An unauthenticated remote attacker can exploit this flaw to reconfigure the backend connection of the service. The vulnerability can result in Denial-of-Service conditions, disrupting normal operations. Additionally, confidential data may be disclosed to the attacker through the misconfigured connection. The CHARX system is used in electric vehicle charging infrastructure, making this a critical infrastructure concern. No authentication is required to exploit this vulnerability, significantly lowering the attack barrier. The advisory was published by CERT VDE under VDE-2026-008. The high severity rating reflects the potential for both availability impact and data exposure.
Technical details
Mitigation steps:
Affected products:
CHARX OCPP Agent
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
