Missing firmware validation allows remote code execution
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Affected products
EVbee · DC-80References
https://csirt.divd.nl/DIVD-2026-00001/