CVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

Scoring

Severity
HIGH
CVSS base score
8.6
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.26%
CWE
CWE-636
Published
2026-07-30
Last modified
2026-07-30

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs