PT-2026-44498 · Unknown · Charging Controller

Lionel R. Saposnik

·

Published

2026-05-28

·

Updated

2026-05-29

·

CVE-2026-9037

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Charging controller (affected versions not specified)
Description A firmware update mechanism fails to validate the authenticity of firmware packages delivered through the device's management interface. Due to the lack of cryptographic signature verification, an attacker capable of interfering with or impersonating the management channel can force the installation of an unauthorized firmware package, potentially leading to the execution of unauthorized code with high privileges on the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-9037

Affected Products

Charging Controller