The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://csirt.divd.nl/DIVD-2026-00001/ |
Configurations
No configuration.
History
13 Jul 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-13 10:16
Updated : 2026-07-13 17:44
NVD link : CVE-2026-22097
Mitre link : CVE-2026-22097
CVE.ORG link : CVE-2026-22097
JSON object : View
Products Affected
No product.
CWE
CWE-347
Improper Verification of Cryptographic Signature
