CVE-2026-44103
Received Received - Intake

Unauthenticated Firmware Injection in JupiCore Service

Vulnerability report for CVE-2026-44103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: CERT VDE

Description

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated remote attacker to inject malicious firmware into the internal charging module. The JupiCore service sends firmware updates without checking their integrity or verifying authenticity, which could let attackers compromise the device's integrity.

Impact Analysis

Exploitation may lead to unauthorized firmware changes, potentially causing device malfunction, data breaches, or allowing further attacks. Attackers could gain control over the device's charging module, leading to broader system compromise.

Mitigation Strategies

Disable or restrict access to the JupiCore service until a patch is applied. Monitor network traffic for unauthorized firmware update attempts. Ensure all firmware updates are cryptographically signed and verified before installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart