CVE-2026-9037

A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.
CVSS

No CVSS.

Configurations

No configuration.

History

28 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 20:16

Updated : 2026-05-29 15:42


NVD link : CVE-2026-9037

Mitre link : CVE-2026-9037

CVE.ORG link : CVE-2026-9037


JSON object : View

Products Affected

No product.

CWE
CWE-494

Download of Code Without Integrity Check