CVE-2026-22097
Missing firmware validation allows remote code execution
| CVE | CVE-2026-22097 |
| Title | Missing firmware validation allows remote code execution |
| Credits |
|
| Affected products |
| Product |
Affected |
Unaffected |
Unknown |
|
EVbee DC-80
|
>=
0
to
< 1.5.1
(semver)
|
|
|
|
everything else |
|
|
| CVSS |
|
| References |
|
| Problem type(s) |
CWE-347
|
|
Date published
|
|
|
Last modified
|
16 Jul 2026 15:41 UTC
|
Description
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.
JSON version.