← back
CVE-2026-22097criticalCWE-347

Missing firmware validation allows remote code execution

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.3epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Affected products
EVbee · DC-80