SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-44094

HIGH · CVSS 8.6 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a vulnerability that forces the system to revert to a firmware partition with insecure settings, including default credentials. This could enable unauthorized SSH access as an unprivileged user, potentially disrupting charging operations. Organizations utilizing affected products should prioritize patching this vulnerability to mitigate the risk of unauthorized access and operational interruptions.

CVE
CVE-2026-44094
Severity
HIGH
CVSS
8.6
EPSS
0.26%

Original NVD Description

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.