Skip to the content.

CVE-2026-22097

Missing firmware validation allows remote code execution

CVE CVE-2026-22097
Title Missing firmware validation allows remote code execution
Credits
Affected products
Product Affected Unaffected Unknown
EVbee DC-80 >= 0 to < 1.5.1 (semver)
everything else
CVSS
Base score 9.3 - CRITICAL
Attack Vector NETWORK
Attack Complexity> LOW
Attack Requirements NONE
Privileges Required NONE
Confidentiality Impact
Vulnerable system HIGH Subsequent systems LOW
Integrity Impact
Vulnerable system HIGH Subsequent systems LOW
Availability Impact
Vulnerable system HIGH Subsequent systems LOW
Safety impact NOT_DEFINED
Automatable NOT_DEFINED
Recovery NOT_DEFINED
Value Density NOT_DEFINED
Vulnerability Response effort NOT_DEFINED
Provider Urgency NOT_DEFINED
References
Problem type(s) CWE-347
Date published
Last modified 16 Jul 2026 15:41 UTC

Description

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.


JSON version.